NetForSE

The FBI reports that 9 out of 10 companies suffered a breach last year. Enterprises have implemented protection technology and automated intrusion detection systems. Incident recovery is left to time-consuming, expensive manual processes that not only delay understanding of the scope of the breach but leaves the enterprise vulnerable to similar breaches until a full analysis is completed.

ACKNet Technologies is developing NetForSE, a network forensics search engine based on an exclusive technology license from Los Alamos National Laboratory. In production for over seven years, NetForSE dramatically reduces the time and effort in recovering from network security violations. A comprehensive Enterprise Security Management (ESM) practice is made up of three integrated disciplines: Protection, Detection and Recovery. Solutions for Protection and Detection are widely available. ACKNetŐs proprietary solution addresses Recovery, which is largely ignored.

ACKNet's network analysis and forensics appliance offers unparalleled performance at a price point that makes ESM affordable for networks ranging from hundreds to thousands of hosts.

  • Scalable, proprietary real-time network forensics search engine
  • Capable of processing hundreds of millions of network events per day.
  • Powerful retrospective and analytical capabilities.
  • Easy to maintain without a skilled database administrator.

These tools help analysts find relevant events and can begin researching quickly, instead of chasing meaningless false positives. This also helps new analyst quickly understand the traffic on the network to get them productive quicker.

Please come back and visit us soon to see the progress of these tools, or email us at info@acknettech.com to receive more detailed information.

Tools

Regex Sniffer

In doing Incident Response and Intrusion Detection, there is often a need to do a search for a certain string. If you know perl and how powerful its regular expressions are, you might find this tool handy. Script will work on an ethernet interface or a pcap file.