Home | Solutions | Technology | Packages| Remote dba | Oracle Monitoring | Unix/Linux Management | Infrastructure Management
     
Intrusion Detection System

Intrusion Detection System

NET VAULT Intrusion Sensors
Built on the legacy of the open source Snort® rules-based detection engine, NET VALT Sensors use a powerful combination of signature, protocol, and anomaly-based inspection methods to achieve the maximum attack detection and prevention capability.

Every aspect of the sensor can be configured and customized to ensure that users detect and prevent the events most important to them. Flexibility in the rules language and the numerous configuration options (port density, interface types, deployment modes for example) allow users to easily define new ways to identify and prevent threats and enforce policies specific to their individual environment.

NET VAULT Intrusion Agents
NET VAULT Intrusion Agents for Snort allow open source Snort users to benefit from the NET VAULT 3D approach while protecting and maximizing their investment in open source Snort deployments. All the intrusion event information from Snort sensors can be aggregated directly into the NET VAULT Defense Center with data from NET VAULT Intrusion Sensors to trigger the ABC's of Defense -- Alert, Block and Correct.

The NET VAULT Control Center

By closely integrating and correlating the threat information provided by NET VAULT Intrusion Sensors and Agents, the NET VAULT Defense Center prioritizes the millions of security events to determine the most critical events to an organization's business, and takes the appropriate actions.

These actions allow users to leverage the ABCs of Defense – Alert, Block, and Correct -- all in real-time, against all network threats.

  • Alert. Automated warnings to individuals or other management systems via SYSLOG, email, SNMP traps, etc. ensure attack warnings are rapidly addressed.
  • Block. Critical threats are not only blocked, but actually contained or quarantined via techniques including dropping traffic, disrupting sessions between devices, and integrating with access control devices such as firewalls, routers and switches.
  • Correct. New vulnerabilities and threats can be automatically mitigated by integrating with patch or configuration management systems to apply configuration or code changes to eliminate possible exploitation.

This high level of contextual intelligence allows customers to determine why a change occurred, whether an attack poses a serious threat to a target, and how to best prioritize and shape the response.
The NET VAULT Defense Center allows security administrators to more effectively secure their networks by providing:

  • A single, central point of administration analysis and reporting
  • Rapid response to potential attacks according to the ABC's of Defense
  • More consistent management and enforcement of security policies and compliance requirements


  © 2004 DATAbase DBA .All Rights Reserved