Presentation is loading. Please wait.

Presentation is loading. Please wait.

The Power of Lossless Packet Capture & Real-time Netflow SANS Tool Talk Boni Bruno, CISSP, CISM, CGEIT Technical Director.

Similar presentations


Presentation on theme: "The Power of Lossless Packet Capture & Real-time Netflow SANS Tool Talk Boni Bruno, CISSP, CISM, CGEIT Technical Director."— Presentation transcript:

1 The Power of Lossless Packet Capture & Real-time Netflow SANS Tool Talk Boni Bruno, CISSP, CISM, CGEIT Technical Director

2 2 Copyright © 2013 You Just Suffered a Major Security Breach! What Happened?! Who Was Affected?! When Will It Be Fixed?! 3 Questions Your IT Staff Better Answer in the First 8 Hours!! Could Your Current SEM/SIEM Tools Cover You for this Security Breach?

3 Visibility & recording infrastructure for high- speed networks Endace provides 100% accurate network recording at 1Gbps to 100Gbps!!!

4 4 Copyright © 2013 Next-Generation EndaceDAG Overview Designed for data capture applications requiring 100% network data capture Three “Feature Bundles” Three Product Configurations Low Overhead Zero Loss Capture Hardware Time Stamps Global Clock Synch In-Band Metadata Classification/filtering Load Balancing

5 5 Copyright © 2013 Endace Network Visibility Infrastructure Network Visibility Headend Allows EndaceProbe INRs/ODE to scale to 40 and 100GbE EndaceAccess™ Network Visibility Headend Endace Open Hosting Platform (ODE ) High Performance Intelligent Network Recording Up to 64 TB storage Mix of 1 and 10GbE ports EndaceProbe™ Intelligent Network Recorder EndaceFlow™ NetFlow Generator Appliance (NGA) Hosting Platform for Monitoring Applications 8x1GbE or 4x10GbE Ports Up to 16 TB internal storage; Fibre Channel support for SAN High-Speed NetFlow Generation for 10GbE Networks 4x10GbE Ports EndaceProbe: Provides 100% packet capture on 10Gb Ethernet links NetFlow Generator: Generate unsampled netflows from 1GbE/10GbE links EndaceAccess: Load-balances 40Gb/100Gb links across multiple INRs Endace ODE: Provide packets for hosted 3 rd party applications

6 6 Copyright © 2013 The Endace Probe Solution

7 7 Copyright © 2013 Monitoring and Recording Fabrics

8 8 Copyright © 2013 100% Packet Capture means 100% Network Visibility

9 9 Copyright © 2013 Can you Pinpoint Microbursts Occurring on your Network?

10 10 Copyright © 2013 Can you Identify Applications Running on your Network?

11 11 Copyright © 2013 Can you Identify Traffic Changes Over Time?

12 12 Copyright © 2013 Can you see Conversations on the Network?

13 13 Copyright © 2013 See Packets in a Browser!

14 14 Copyright © 2013 100Gbps Packet Capture…

15 15 Copyright © 2013 Time Synchronization

16 16 Copyright © 2013 Security Architecture Full Content Repository Current Security Infrastructure: Firewall IDS/IPS DLP End Point Security Events pcaps Event-driven “snippets” and/or ALL traffic recorded into a rolling buffer Alarm Search & Analysis Event / Log Repository Packet Storage SIEM (Security Info & Event Mgmt) Packet Capture

17 17 Copyright © 2013 SIEM Integration via RESTful API

18

19 19 Copyright © 2013 Netflow – The New Way!!!

20 20 Copyright © 2013 Netflow – The New Way!!!

21 21 Copyright © 2013 Suspect Identify Mitigate Impact Tools Fixed Permanent Protection Security Incident Lifecycle

22 22 Copyright © 2013 Security Incident Lifecycle Unique EventCan lead to repetitive events if not correctly identified…

23 23 Copyright © 2013 Security Incident Lifecycle

24 24 Copyright © 2013 Security Incident Lifecycle Reduced Frequency Minimize Scope of Impact Faster Remediation ID Root Cause

25 25 Copyright © 2013

26 26 Copyright © 2013


Download ppt "The Power of Lossless Packet Capture & Real-time Netflow SANS Tool Talk Boni Bruno, CISSP, CISM, CGEIT Technical Director."

Similar presentations


Ads by Google