NetWitness® Technology-In-Depth

The NetWitness product suite represents over 10 years of innovative research and development that produced a portfolio of patented systems and methods for network traffic monitoring and analysis. Vastly different from any existing security and network infrastructure technology, Netwitness NextGen™ was designed from the ground up to instantly analyze, model and mine all network traffic in unprecedented detail, not simply monitor it.

How is NetWitness NextGen™ Different?
Central to what makes our product suite a true enabler, and augmentation to your existing infrastructure is the NetWitness® MetaFlow Engine. This patented technology extracts session application and content descriptors from network traffic and produces a common language that normalizes all network entity activity across every application. The NetWitness metadata, combined with its native full packet storage, is the technical foundation of a network recording infrastructure capable of providing insight and behavior detail into every conceivable network event: internal, external, malicious or benign.

The NetWitness NextGen™ Architecture
The NetWitness NextGen™ Product Suite is architected for ultimate reuse and flexibility across any environment. At the core of the architecture are server products, Decoder and Concentrator, that establish a record once/reuse many times packet capture infrastructure. These products have an open API that enables any application to query and request network data from them. This API is the foundation of Investigator and Informer, the first of many applications that will be available for the NetWitness NextGen™ framework.

NetWitness NextGen™ Technology Highlights
  • No Host-Agents Required
  • Solutions are offered as software and hardware
  • First available IPv6 session analysis product
  • FIPS 140 compliant communications infrastructure
  • Low-cost, scalable SAS storage - up to 225TB per capture location
  • Supports live packet capture and packet file import
  • Provides full application layer analysis and content search
  • Available API/SDK
  • Provides protocol and application exploitation of: HTTP, FTP, TFTP, TELNET, SMTP, POP3, NNTP, DNS, HTTPS, SSL, SSH, Vcard, PGP, SMIME, REGEX, DHCP, NETBIOS, SMB/CIFS, SNMP, NFS, RIP, MSRPC, Lotus Notes®, TDS(MSSQL), TNS(Oracle®), IRC, Lotus Sametime®, MSN IM, RTP, Gnutella, Yahoo Messenger, AIM, SIP, H.323, Net2Phone®,Yahoo Chat, SCCP (Cisco® Skinny), Bittorrent, GTALK, Hotmail, Yahoo Mail, GMail, TOR and others.



 Support Partners Blog