'Google-Like' Tool Aids Network Security

Network administrators and security specialists have long had tools and software for analyzing the streams of traffic that course through company systems, but now a Marlborough, Massachusetts, startup wants to make the process a lot easier.

By Chris Kanaracus
Wed, June 03, 2009

IDG News Service — Network administrators and security specialists have long had tools and software for analyzing the streams of traffic that course through company systems, but now a Marlborough, Massachusetts, startup wants to make the process a lot easier.

Dejavu Technologies recently released TrafficScape, an appliance that grabs network packets and converts them into XML documents, which are then pulled into a database that is searchable through a simple, Google-like toolbar.

The company is aiming the software at average investigators who may have the instincts needed to make smart searches through reams of data, but who lack specialized technical training, according to CEO John Ricketson.

"When it gets to dealing with networks, there are a lot of low-level engineering skills required. We're trying to get tools that domain experts can use," he said. Such individuals need to "have the tool get out of [their] way."

TrafficScape can capture a wide range of protocols and document types, including email, VoIP calls, instant messages, PDFs, Internet searches, and various other forms of data, according to the company. Searches can be done in "near real time" or against a stored data set.

Users can employ simple keyword searches or construct more granular Boolean queries, such as for all network documents containing the words "aluminum," "shipment" and "Dejavu," according to a demonstration.

The tool also allows searches that employ network attributes -- information such as IP addresses and user IDs that are tied to a given conversation. Therefore, one could search for all exchanges between two particular users, in which a certain keyword or words crop up.

Conversations with many network transmissions, such as an instant messaging session, are captured and organized as a group within a single document. Even the buddy lists associated with a chat get captured, giving investigators a potentially broader view into a target's identity and associations.

Beyond ease of use, to differentiate TrafficScape in the market, Dejavu is planning to home in on Web 2.0 data, such as the various information streams that flow to and from complex social networking sites like Facebook, Ricketson said.

The next version of the product will also add automatic text transcription of VoIP calls and video streams, which will be indexed and searchable.

While Dejavu may have a couple of new twists on the formula, a range of other companies, such as PacketMotion, have been selling various types of network traffic analysis tools for some time.

Therefore, TrafficScape has to make the right strategic moves as it enters the fray, according to Forrester Research security analyst John Kindervag.

Continue Reading

This paper covers power utilization, intelligent power management and industry best practices for energy efficiency. Extreme Networks® takes a lifecycle approach to power efficiency, management and recycling, offering savings to our customers and promoting a greener world.
Virtualization and cloud are driving new requirements for data center network performance, VM support, automation and simplified orchestration. This paper outlines Extreme Networks® open fabric approach to high speed, low latency networks for modern data centers.
The evolution of the network to provide the intelligence needed to address user, device and application mobility is underway. In this white paper, Extreme Networks® outlines the five phases required to bring mobility into the network.
The McAfee virtual patching solution provides a layered approach to security risk management, while adding the ability to apply a virtual patching strategy to your existing change-management process.
Learn more about Gartner's evaluation of network IPS that places McAfee in the leaders' quadrant. Deep inspection network-based intrusion prevention continues to be a due-diligence security control.
IP networks are growing at an exponential rate thanks to virtualization, mobile devices and IP v6. But IT departments are under budget constraints and skilled staff is becoming scarce. The solution..
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and enterprise campus network infrastructures for the Cloud, and identify ways to better allocate network resources, reduce operating costs and improve application performance.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
Today's networks are under attack. To build a better network, you've got to understand the stresses that today's networks are under due to mobility, virtualization and cloud computing.
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center