About Us  |  Services  | Recruitment  |  Advertise  | Contact

 

Computer Network Defence Ltd

IDS & IPS Products
Scanning Products
VPN & Firewall Products
Forensics Solutions
Anti-Forensics Tools
Forensic Toolkits
Forensic Tools
Network Forensic Tools
Password Cracking
Content Protection
Training Courses
Raw Packets
Bug Sweeping / TSCM
Miscellaneous
Services


Network Forensic Tools
These products provide a network forensic capability.  They record, store and analyse/display all network data and are therefore best served as inline appliances. These products can also reconstitute much of the data enabling the investigator to view the data as it was sent or how it would be received.  

Greg Shipley's Network Forensic Tools Review

See Also Protocol Analysers and Full Packet Capture Appliances



Links to Products

NetDetector

NetIntercept

eTrust

 

NetDetector

 

Niksun

http://www.niksun.com/Products_NetDetector.htm

NetDetector acts as a Security Camera and Motion Detector for your network by continuously capturing and warehousing network traffic, and  alerting on specific signatures and traffic patterns. Built-in modules provide complementary signature and statistical anomaly detection, thus locating the "needles" of actionable information in the "haystack" of raw data. Advanced reconstruction capabilities allow for detailed review of  web, email, IM, FTP, Telnet, and other applications. All this and more is rounded out by a highly intuitive web-based GUI thus eliminating the need to load a special client application. As a single appliance the NetDetector suite offers a powerful security surveillance solution in it's own right. When appliances are distributed throughout the enterprise and then centrally managed along with aggregated reporting and analysis, a new unprecedented level of security monitoring unfolds.

COMMERCIAL

Information Updated:04 Nov 2004


NetIntercept

 

Sandstorm

http://www.sandstorm.net/products/netintercept/

NetIntercept 3.0 captures LAN traffic using a standard Ethernet interface card placed in promiscuous mode and a modified UNIX kernel. Long-term archival storage of captured data in NetIntercept is accomplished by storing the raw dump files.  Depending on the hardware options selected, the archived dump file can be written directly to a removable media device attached to the NI machine, or transferred over the network to other machines for archiving. NetIntercept performs stream reconstruction on demand. When the user selects a range of captured network traffic to analyze, NetIntercept assembles those packets into network connection data streams. The reconstructed streams are then presented to the NetIntercept analysis subsystem for identification and analysis. The protocol recognition system is fully modular, making the parsing of data streams clean and easily extensible. The modules are arranged in a hierarchical tree. Each module specializes in a particular protocol, and may pass portions of the data stream to child modules for lower-level analysis. Modules that extract data useful as search criteria or for statistical purposes store that information in an SQL database.

COMMERCIAL

Information Updated:o4 Nov  2004


CA Network Forensics

 

Computer Associates International

http://www.ca.com/us/products/product.aspx?ID=4856

Capture raw network data and use advanced forensics analysis to identify network exploits, data theft, and security or policy violations.

Examine network relationships regardless of physical topology, visualize traffic patterns in behavioral clusters and quickly obtain a graphical depiction of communications. Empower your security and incident response teams to assess, investigate and inform. CA Network Forensics enables you to reduce investigation costs, while improving efficiencies in security planning, deployment and recovery.

COMMERCIAL

Information Updated:01 Nov 2007

Click Here To Go To The Top Of The Page

Last page update:  01 Nov 2007

Computer Network Defence Ltd
Information Security Consultancy and Recruiting
enquiries@securitywizardry.com 

Copyright © 2004 Computer Network Defence Ltd. All Rights Reserved.

PO Box 2680, Corsham, Wiltshire, SN13 0ZR, UK
Phone       0870 3219014
International +44 (0) 1225 811806