Upcoming Events

Where the Cloud Touches Down: Simplifying Data Center Infrastructure Management

Thursday, July 25, 2013
10:00 AM PT/1:00 PM ET

In most data centers, DCIM rests on a shaky foundation of manual record keeping and scattered documentation. OpManager replaces data center documentation with a single repository for data, QRCodes for asset tracking, accurate 3D mapping of asset locations, and a configuration management database (CMDB). In this webcast, sponsored by ManageEngine, you will see how a real-world datacenter mapping stored in racktables gets imported into OpManager, which then provides a 3D visualization of where assets actually are. You'll also see how the QR Code generator helps you make the link between real assets and the monitoring world, and how the layered CMDB provides a single point of view for all your configuration data.

Register Now!

A Network Computing Webinar:
SDN First Steps

Thursday, August 8, 2013
11:00 AM PT / 2:00 PM ET

This webinar will help attendees understand the overall concept of SDN and its benefits, describe the different conceptual approaches to SDN, and examine the various technologies, both proprietary and open source, that are emerging. It will also help users decide whether SDN makes sense in their environment, and outline the first steps IT can take for testing SDN technologies.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Rollout: Mazu Profiler 8

More than one in four U.S. financial institutions will purchase a network behavioral analysis system this year, according to Gartner. We think that's a believable projection--after all, in this post-TJX world, what you don't know about that's accessing your network can get you fired.

THE UPSHOT
CLAIM: 

Mazu promises to help IT better understand how users, applications, and systems interact on both the LAN and WAN. Profiler analyzes network flow statistics and performs deep-packet inspection to reveal hidden issues that impact both service quality and security.
CONTEXT:  Mazu competes with the likes of Arbor Networks, Lancope, Q1 Labs, and Sourcefire. Mazu is a top player in the network behavioral analysis market, and its Profiler appliance is priced as such, running up to $150,000 for a typical enterprise deployment.
CREDIBILITY:  Profiler 8 is a robust network analytic product, but its security features may overlap with intrusion-prevention systems. Still, Profiler's ability to integrate with third-party network management and security tools will help IT build a comprehensive reporting and security strategy.

Network behavioral analysis, or NBA, has matured from a niche technology into a necessary element in a comprehensive security strategy, but these products aren't just for the security team: The insight they provide about users, applications, and network performance will be useful across the organization, a factor that can help make their high cost palatable.

We put Mazu Networks' Profiler to the test in our Boston Real-World Partner Labs and were impressed with its ability to alert on suspicious traffic, though we would've liked more reporting on latency, and the GUI could use polish.

The magic behind NBA products, including Profiler, is the network flow technology found in switches and routers. Cisco helped pioneer the concept with its NetFlow packet flow analysis, based on the IPFIX open standard. NetFlow records provide information that can be used to manage availability and performance and to troubleshoot problems. Extreme Networks, Foundry Networks, and others use a similar open standard, SFlow, that differs from NetFlow primarily in the way data is collected. This Layer 3 network analysis is great for a general bird's-eye view of how your network is being used, but what about security? Today, clever worms and peer-to-peer applications can hop ports, even tunnel inside traffic deemed legitimate. To beat them at their own game, you can use port and/or VLAN mirroring to send a copy of the entire packet to an NBA system like the Mazu Profiler for analysis. This way, the unique characteristics of worms and P2P apps can be detected through deep inspection. The Profiler we tested can accept mirrored traffic at full interface speed via its dual Gigabit Ethernet interfaces. However, the remote office sensor sent for review was capped at a 45 Mbps sample rate--fine for flow analysis, but not fast enough for deep packet inspection.

TAKE A GOOD LISTEN

We placed the core Profiler collector appliance in a live production network comprising 30 edge switches and a core Layer 3 switch, all from Extreme. Before going live with our testing, we took advantage of Profiler's ability to import, in bulk, the management IP addresses of all switches and routers in our infrastructure. At the same time, we added all of the subnets on our internal network so Profiler could determine which address spaces exist inside and outside the core. Last, and most important, we let Profiler listen in on network activity for a couple of weeks to establish a baseline of normal behavior. Once the appliance has a general picture, we could turn up the device's heuristical analysis capabilities to get alerts on suspicious events.


Page:  1 | 23  | Next Page »


Related Reading


More Insights


Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | Please read our commenting policy.
 
Vendor Comparisons
Network Computing’s Vendor Comparisons provide extensive details on products and services, including downloadable feature matrices. Our categories include:

Research and Reports

August 2013
Network Computing: August 2013



TechWeb Careers