NetWitness monitoring tool spots security violations - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Security

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

BitTorrent blocking; SQL injection attack. Listen now!

Network World 360

Hacker writes Cisco rootkit; Microsoft launches online telescope. Listen now!

Network World 360

Additional Resources

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Discover how to Create an Orchestrated Data Center through Virtualization Novell

IT professionals like the idea of consolidating hundreds of servers into only a few, but it takes a lot more to cost effectively consolidate and virtualize servers. Watch this six-chapter webcast, "Reduce Complexity and Cost - Windows Server Consolidation with Virtualization" to learn how to effectively consolidate your Windows environment. One of the themes explored includes the characteristics of an orchestrated data center, which includes: Resource management, dynamic provisioning, job management, policy management, accounting and auditing and real-time availability. Learn more about orchestration and much more today. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

it's ture, at least for the time being, people living in china cann't access to blogspot, wikipedia(the...- someone_who_s_in_china

Join the Discussion

NetWitness monitoring tool spots security violations

NextGen data-capture and analysis tool looks for security threats and policy violations.
By Ellen Messmer , Network World , 09/10/2007
  • Social Web 
  • Email 
  • Feedback 
  • Close

Start-up NetWitness Corp. Monday announced a security product called NetWitness NextGen that monitors, records and analyzes traffic inside the corporate network to spot security threats and policy violations.

“We’re looking at it from an application and user-level perspective,” says Amit Yoran, NetWitness chairman and chief executive. “It’s based on what you want to be notified about—for instance, failed log-in attempts, or someone at some address switches to the administrator’s account, gets a document and sends it to a printer—any series of events that raises questions.”

Yoran, formerly National Cyber Security Director in the U.S. government’s Dept. of Homeland Security, founded Herndon, Va.-based NetWitness last November with the company’s president Nicholas Lantuh, formerly vice president at ManTech International.

ManTech had acquired an earlier version of NetWitness called Analytics with its purchase of CTX Corp., which had first developed the network-security analysis tool primarily for national-intelligence agencies.

With about $7.5 million in private funding, Yoran and Lantuh bought out the NetWitness product assets and founded the company, which now has 30 employees, to further develop it for more general use. NetWitness can be seen as competing against firms such as Niksun which provide security traffic analysis tools, and the data-leakage prevention firms such as Vontu or PortAuthority (which was acquired by Websense).

NetWitness NextGen is considered the eighth version of NetWitness and it includes server-based components called Decoder and Concentrator which passively record up to 180 terabytes of traffic and also may be used with a storage area network to boost storage capacity.

A tool called NetWitness Informer provides alerts and reports and can analyze traffic according to the Payment Card Industry data standards and the federal government’s Federal Information Security Management Act (FISMA) program.

NetWitness Investigator, a network-analytics workstation, connects to Decoder and Concentrator to search terabytes of captured traffic data and provide forensics and threat analysis through a visual display.

1 | 2 |  Next >
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code