Network World
Sunday, November 8, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Network behavior monitoring as security measure

Related links

Management Notes RSS feed

E-mail Denise Dubie

Management Notes archive.

Security forum
Discuss Management Notes and other Network / Systems Mgmt topics.


With next week's RSA Conference in San Jose, the talk among several management vendors has turned to security.

As many tout their identity management or security information management (SIM) suites, others are focusing on another area of network management that has been coming to the forefront as a unique defense against the most insidious attacks: network behavior analysis, network anomaly detection systems or network behavior anomaly detection. While the market works on what to call the technology, the technology itself performs traffic monitoring and analysis for security purposes.

Generally speaking, these types of products perform a benchmark of normal traffic behavior and continuously monitor for changes. Then if, for example, a relatively unused host begins to propagate many requests, the anomaly detection system might suspect the host could be falling victim to a worm. Or if enterprise application traffic deemed content-sensitive starts to use Port 80, the port left open on firewalls for Internet traffic, the products could alert that compliance policies could be in the process of being breached.

The products, according to industry watchers, perform multiple IT tasks in the realm of security, compliance and management. In fact, tools for monitoring traffic for potential breaches is becoming a staple in most security managers arsenal. According to Gartner, by the end of 2007, 25% of large enterprises will employ such tools as part of their network security strategy.

Companies such as Arbor Networks, GraniteEdge Networks, Lancope, Mazu Networks and Q1 Labs separately offer products that perform this type of traffic monitoring and behavior analysis of known and unknown threats. Even Cisco's MARS (Monitoring Analysis and Response System) performs network anomaly detection to some degree.

Back to Management Notes

Comments

Post a comment

Name:


E-mail address:


URL:


Comments:


Remember info?




Network World Newsletter

Sign up for some of our Network/ Systems Management newsletters.

Network Optimization
Network Systems Management Alert
Virtualization Alert
IT Careers and Training  Alert
Network World Daily
 All newsletters  

E-mail Address:


Partner Content

NetScout and analyst Jim Metzler have teamed to deliver a series of IT Briefs on Network and Application Performance Management leveraging research from NetScout's nGenius & Sniffer users.

www.netscout.com

Metzler on Service Delivery Management

Delivering IT business value by evolving our thinking from managing application performance to focusing on services.

Learn More

2009 Handbook of Application Delivery

Successful IT organizations must know how to make the right application delivery decisions in these tough economic times.

Download the Handbook

Metzler on the Modern IP Network

Discusses the growing emphasis on network management and the need to implement a holistic view of the end-to-end experience of the user.

Read the Brief