The recently published ESG Research Report, "U.S. Advanced Persistent Threat Analysis," underlines the need for granular approach to network security for organizations that traditionally collect data from a number of sources like log files and NetFlow, and then organize and analyze this data using tools like log management and SIEM, according to NetworkWorld.
To ensure network security, organizations require granular details about the network that include network behavior, payload analysis, packet analysis, application-layer analysis, network performance and more from layers 2 through 7 of the OSI stack.
The data given in the report reveals that large organizations are unaware of what is happening in their network. This leaves them vulnerable to attack.
The report says 68 percent of organizations depend upon network management tools to determine if they are experiencing a cyber attack. The next closest response was "log file analysis" at 51 percent, NetworkWorld report said.
Further, among those organizations that have created or modified security processes in response to APTs, 52 percent have, "improved network traffic monitoring for attack patterns or other anomalous behavior." Among those who have purchased new security technologies in response to APTs, 42 percent purchased network behavior monitoring technologies.
The findings of the study underline the need for better network security solutions. Leading network security players like Cisco (News
- Alert) can bring a dramatic change in the situation by heavily focusing on network monitoring technologies for security and performance, says Jon Oltsik, principal analyst at NetworkWorld.
Network monitoring companies have already realized the increasing demand from the industry. There has been growing interest for open source network monitoring tools like Suricata, HTTPry, and Sguil as cost-effective alternative to traditional tools, Oltsik added.
A number of acquisitions are also on the cards for the industry. One such acquisition as highlighted by NetworkWorld is the acquisition of NetWitness by RSA. Oltsik also urges network monitoring pure-plays like Compuware, ManageEngine, NetScout, NetQoS (News - Alert), Net Optics, NetScout, and Quest to take advantage of this opportunity.
Oltsik concludes saying that organizations should not limit their focus only to monitoring. With better data and analytics, CISOs can take automated actions to enforce granular policies.
Meanwhile Plixer International (News - Alert), a provider of NetFlow Traffic Analyzer, announced their new NetFlow product, which is designed to help identify top talkers throughout the network, who they talk to and what they do.
The tool comes with an innovative, easy to use graphical interface to help make analyzing where problems exist much easier, and present the information in such a way that it becomes an easier sell to management.
Rajani Baburajan is a contributing editor for TMCnet. To read more of Rajani's articles, please visit her columnist page.
Edited by Rich Steeves