Skip to content

Network traffic monitoring and intrusion detection

The appliance inspects a copy of your traffic, matches it against a signature database and raises an alarm when something happens that should not.

categories of security events
43categories of security events
alert severity levels
4alert severity levels
raw traffic export
PCAPraw traffic export
Network activity · Statistics
Дашборд модуля «Сетевая активность»: счётчики критических событий, предупреждений и уведомлений, диаграмма по времени и шесть круговых диаграмм по категориям, сигнатурам, протоколам, IP-адресам и портам
A summary for the selected period: counters by severity, event distribution over time and six pie charts. Clicking any segment opens the log filtered by it.

How it works

The module starts together with the appliance software and runs continuously. It captures traffic from the mirror port and compares it against a set of signature rules. When traffic matches a rule, an alert with a category and a severity level appears in the log.

From there you can work with that alert: open the event details and the text of the rule that fired, download the related slice of traffic as a pcap file or open it right away in the built in viewer. The engineer never has to switch tools.

A network map is built separately: nodes are addresses, links are flows between them. It answers a question that usually goes unanswered in a large network: who actually talks to whom, and at what volume.

What the appliance treats as a security event

Categories come from the rule base and fall into four severity levels. Below are the real names from the interface.

Critical
  • Network trojan detected
  • Malware command and control activity detected
  • Command and control domain detected
  • Exploit kit activity detected
  • Attack on a web application
  • Attempted and successful administrator privilege gain
  • Successful credential theft detected
  • Executable code detected
  • Targeted malicious activity detected
Warnings
  • Denial of service attack detected
  • Large scale information leak
  • Cryptocurrency mining activity detected
  • Login attempt with a default username and password
  • Device receiving an external IP address detected
  • Potentially unwanted program detected
  • Possible social engineering attempt
  • Access to a potentially vulnerable web application
  • Client used an unusual port
Notices
  • Network scanning detected
  • Suspicious string detected
  • Protocol command decoding
  • General ICMP event
  • Unknown traffic
Network activity · Log
Журнал оповещений сетевой активности: время, интерфейс, IP и порты источника и назначения, протокол, сигнатура и SID сработавшего правила
Every event with its exact time, interface, addresses and ports of both sides, protocol, the name of the triggered signature and its SID.
Network activity · PCAP viewer
Встроенный просмотрщик PCAP: график взаимодействий, таблица пакетов, дерево разбора протоколов и HEX-представление байтов
Dissection of a specific packet: protocol tree and bytes in HEX. The file opens straight from the log, no Wireshark installation required.

What you can configure

Custom detection rules

Any system rule can be copied into your own set and rewritten for your infrastructure: action, protocol, addresses and ports of both sides, direction, category, signature text and tags. Custom rule numbers are taken from the range 1,000,000 to 2,000,000.

Enabling and disabling system rules

A rule that only creates noise in your network can be switched off straight from the log or from the system rules list, without restarting the whole appliance.

Filters and reports

The log filters by time, interface, addresses and ports, protocol, category and signature. The filtered result exports to HTML, JSON or XLSX with aggregation by a chosen field.

We will prepare a quote for your network

Tell us about your infrastructure: how many sites, which switch sits in the core, whether you already run a SIEM. We will pick the edition and the connection scheme, and calculate the cost.

  • We reply within one business day
  • We design the connection scheme for your topology
  • We show the interface on a live demo unit

Request a quote

Leave a phone number or an email so we can reply.

By submitting this form you agree to our privacy policy.