Niksun NetDetector

Niksun's NetDetector goes way beyond simple network-based forensics. This appliance features not only the ability to do forensics and incident analysis, it also has an intrusion detection system and can do complete network security surveillance.

Beyond analysis deep within the packet, this product can also reconstruct applications such as web browsers and even chat and web-based email.

We found NetDetector quite easy to use. Setup takes just a few minutes and most of this is spent unpacking the appliance. Initial configuration can be done either by connecting a monitor and keyboard directly to the appliance or through a hyperterminal connection.

After entering a few commands to set time and date, a wizard helped set IP addresses and IP settings such as DNS and gateway. Once that was completed we just plugged it in to our network tap and accessed the Java-based web GUI, which is easy and intuitive to navigate.

This solution is a solid performer. It sits off of a hub, span port of a switch or a network tap, so it sees all network traffic and is able to record anything that goes in or out of the enterprise. When doing analysis, we found drilling down into the many graphs an easy task and finding the exact data was quick and efficient.

This product comes with two main guides. A printed customer installation guide provides the initial setup and installation procedure to get the box up and running, plus clearly shows different tap and network connections. The user guide illustrates the different functions and features of the appliance in great detail. Both manuals include many screenshots and diagrams.

Customers get one year of support with the purchase of the Niksun appliance, consisting of phone and email assistance as well as access to a dedicated web portal. The latter includes access to the latest technical advisories, FAQs, worm/virus notes, learning tools and product documentation.

At a price starting at US$10,000, this product is an excellent value for the money. The combination of analysis capability and application reconstruction, along with simple intuitiveness, makes it a solid asset to almost any organisation.
Niksun NetDetector
Verdict
5 out of 5
For: Easy to use, with deep drill down and application reconstruction ability
Against: Nothing we found
Verdict: A solid product that not only provides good log analysis, it has the forensics chops to get the investigative job done. Our Best Buy
Info
Supplier:
Niksun
Keywords
Related

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read