LONDON (UK): Lancope, Inc. is unveiling its new PacketWatch™ solution for intelligent packet capture this week at Infosecurity Europe 2015. With the PacketWatch solution, large enterprises can obtain deeper network visibility and more granular security context for streamlined incident response and forensics – at a fraction of the cost of full packet capture.
“Full packet capture solutions create massive volumes of data, making it difficult and costly to store all of the information, and also challenging to find relevant security details amidst a deluge of innocuous traffic,” said Kerry Armistead, vice president of product management for Lancope. “PacketWatch alleviates these challenges by enabling organisations to conduct intelligent packet capture for select areas of the network where an issue is suspected – dramatically reducing storage requirements and costs while making it easier to extract actionable data for fending off sophisticated cyber-attacks.”
When collected and analysed with an advanced security analytics platform like Lancope’s StealthWatch® System, NetFlow and other types of network telemetry provide critical metadata for detecting dangerous cyber threats. However, there are instances when security and forensic analysts may want to obtain additional insight by analyzing the corresponding packets from anomalous network conversations.
The StealthWatch System for flow-based monitoring combined with PacketWatch for intelligent packet capture provides an ideal solution for obtaining comprehensive levels of network and security insight. With the PacketWatch solution, packets can be collected and stored for finite network segments and periods of time, and analysed to gain added threat intelligence for detecting and investigating specific network and security issues.