"Introduction to Network Forensics"


Download the PDF

What is Network Forensics?

You can't stop what you can't find. That's why you need network forensics. Active network forensics makes all network data flows instantly visible and replayable, enabling administrators to detect the full source, scope and context of any network security event and protect the network against further attack. Combining high-speed data capture, indexed storage, and comprehensive analysis tools, active network forensics is analogous to putting a security camera on your network. Doing so instantly exposes any specific network event, making even the most sophisticated and targeted network attacks plainly visible.

 

Active network forensics provides real answers to crucial security questions, including:

  • How much critical data is there on the network and where is it going?
  • How can we determine what happened before a network outage, security breach, virus infection, or any other security event?
  • What can be done to ensure compliance to government or internal mandates?

Why You Need Network Forensics

Like a police force, network security products cannot prevent every criminal act. There are simply too many vulnerabilities and clever perpetrators to expect that your organization can forever avoid a security breach. The number of attacks is skyrocketing globally and the associated economic damage has become alarming. Astute organizations now understand the need to shift resources from a simple "prevention" mode to a complete detection and remediation system. After all, the worst attacks are the ones you never know about.

Active network forensics levels the playing field by allowing network administrators to "see" attacks, understand their root cause, and then configure the network to prevent their recurrence. Unlike slow, simple network data capture devices that require tedious analysis of sample data by skilled security administrators, Solera Networks' active network forensics appliances enables effective interrogation of any event. They capture everything at 10 Gbps speeds, and can easily isolate specific events and then assemble a complete picture of what occurred, enabling a swift and effect response by network personnel, even those with only modest security skills.

Solera Networks CEO explains network forensics

Richard Stiennon interviewing Steve Shillingford at RSA SF 2009

Richard Stiennon
 
 

CSI Webcast

The Case for Network Forensics

Case for network forensics webinar
 
 

Introduction To Network Forensics

You can't stop what you can't find. That's why you need network forensics.

 
 

Need For Network Forensics

Examples from the media of why current security tools and strategies aren't enough

 
 

Total Network Recall

Your network security devices will FAIL

 
 

Negative Day Threat Detection

When zero day threat prevention is not enough