"... As a result of our NitroSecurity implementation, we have not had a single [virus outbreak] and we virtually eliminated illegal file-sharing"
— Director of Network Operations & Information Security Officer, Berry College
 

    Quick Contact

    First Name:

    Last Name:

    Company:

    Email:

    Phone:

    State:

    What can we do for you?

      


    Click here for more contact options.

  •  

 
 

NitroView Security Information and Event management: more data for better SIEM, total compliance

Database Monitor




The Industry's only Content-Aware SIEM™

NitroView Enterprise Security Management, content aware SIEM
How to Buy
Contact Us to request a demo, or
call us at 888-LOG-SIEM

Features at a Glance
Full collection, correlation and reporting of:
  • Security alerts and events
  • Logs from devices, servers, and applications
  • Network flow information
  • Database activity
  • Application content

Ultra-fast architecture delivers performance and scalability
  • Collect data at 100,000 eps without compression
  • Collect data at 1,000,000+ eps with compression
  • Query collected information in seconds, produce full reports in minutes
  • Calculate baselines and trends in real-time
  • Instantly pivot or drill into data
  • Store years of data and access, analyze and report on it all

The only Content-Aware SIEM
  • Full visibility into application use and data access
  • Correlate application contents against other observed network activity and logs for maximum threat detection
  • Track user activity across applications and systems
  • Monitor and enforce business policies

Built-in support for all major compliance mandates:
  • HIPAA
  • HITRUST
  • NERC-CIP
  • PCI
  • SOX


Fully integrated with all NitroView products

Fully support for most third party network and security devices, including switches/routers, firewalls, IDS/IPS, anti-virus, application whitelisting, operating systems, privacy solutions, and even mainframes.

Easy to use, distributed appliance-based architecture

More Information
NitroView Enterprise Security Manager (ESM) Datasheet
NitroSecurity Solution Brochure
Awards
Testimonials
ESM Product Specs

NitroView Enterprise Security Manager (ESM) is the industry's only Content-Aware SIEM. That means NitroView can collect, analyze and report on the contents of application data, derived through direct monitoring using NitroView Application Data Monitor, or from third party application inspection and data monitoring solutions. Content-Aware SIEM allows you to answer more questions that are relevant to your security and compliance efforts, such as:

  • Enforce corporate policies for application and data use
  • Monitor and log access to and use of sensitive data
  • Detect data loss and fraud
  • Detect application and protocol anomalies that might indicate an advanced persistent threat (APT)

How can NitroView do this? It all originates from NitroView's advanced data management architecture, which enables NitroView to:

  • Collect more data from more sources
  • Index all relevant information across all sources
  • Analyze all data in real-time to detect threats and anomalies
  • Access all data quickly for rapid incident response and lightening-fast reports

The best part is that NitroView is easy to deploy, offered in a variety of drop-in appliance models to support anything from the smallest network to the largest, most demanding enterprise. Deploy everything you need in a single appliance, or use dedicated appliances in a fully distributed and redundant architecture. Whatever your requirements are, you'll interact with NitroView the same way: via a single, easy to use console that puts the most common security and compliance functions no more than a single click away. Unlike SIEM "suites," the functions of NitroView are tightly integrated, providing a common interface for ease of operation, and a common back-end data engine for truly integrated information management.

Integration has its benefits, and for NitroView this means central device management, network discovery and flow management, policy management and enforcement, event management, log management, and full security and compliance reporting, all from a single pane of glass. This makes deployment simple for smaller networks, and in larger Fortune 100 accounts, it means the difference between

All information—whether from our own NitroView DBM, NitroGuard IPS, or NitroView ELM products, or from virtually any third-party data source—is stored and analyzed together, in a common NitroEDB database. This allows extremely granular indexing for accurate correlation across almost any source, and unprecedented performance for fast forensics and ad-hoc reporting.

The result is more than just a SIEM: it's a powerful information collection, storage an management system that integrates many functions of information security into a single cohesive solution. NitroView's capabilities include:

Security Information & Event Management (SIEM)

NitroView ESM excels as Security Information & Event Management system because NitroView is able to collect, correlate, and analyze more data from more sources than other SIEMs. The availability of network topology and flow data—alongside event, asset, user identity , and application—allows NitroView to easily track users, trace attack vectors, and perform other complex information security tasks. NitroView essentially combines Log Management, Network Analysis, and Security Information & Event Management (SIEM) into a single solution. By combining the real-time collection and analysis of network— and security— based information with real-time log analysis, NitroView ESM provides a unified, holistic approach to security management that is greater than the sum of its parts.

"As hot as a Fourth of July firecracker ...Forget simple SIM/SEM products or traditional log correlators. NitroView blows them all away"

Peter Stephenson,
First Look: NitroView ESM, SC Magazine
pdf read the review

The Power of NitroView: Tracking Users Across Multiple Applications

Using a Database Monitoring tool such as NitroView DBM, it's simple to determine the user responsible for malicious data access. But what if the application used to access the database uses pooled accounts? Knowing that user 'web_serverapp_1' stole your data isn't good enough; you need to know the identity of the actual person who was responsible.

By bringing Database Activity, application logs, network topology information, network flow data, and other relevant information together for common analysis, NitroView ESM is able to correlate the activity of 'web-serverapp-1' with the user logged into that account ... or any account on any other application. Once the user is identified, locating them in the network is also easy through the correlation of network topology and flow information, which is all made instantly available by NitroView. You're even able to discern what that user might have done with the data that he or she access against policy, by analyzing the OS logs of the user's PC to see if the information was printed, saved to a removable disk, or emailed.

information security
security management Topology View
Topology Drill Down
Attack Severity
Users
Application
SIP
Dest Prt

The unification of Security Management into a single system allows previously separate data to be correlated and analyzed together, identifying relationships between network activity, security alerts, and events originating from device logs (including server, host and application logs). By looking at this information as a whole, and providing real-time analysis of all collected data, NitroView is able to apply anomaly detection and event management across the entire expanse of Information Security needs.


Real-time data management engine

NitroEDB NitroEDB is a high-performance relational data management engine that enables many of the advanced features found in NitroGuard and NitroView. The importance of this performance gain can not be overstated: it allows for NitroGuard to operate at high throughput, with a high number of concurrent sessions, while at the same time analyzing flow data for anomalies. It also provides data management performance high enough to support a real-time user interface, where queries and analytics are returned in seconds, even on massive amounts of historical data — and without effecting NitroGuard's ability to continue processing new events.

Performing Historical & Analytical Management in Real-Time

Slow data access has created a barrier between Security Event Management — which must occur in real-time — and other SIM functions such as behavior analysis and forensics — which require good samples of stored data to provide real value. With NitroView ESM, you can finally do both at once. Our relational data management engine is able to perform complex data lookups and analytical calculations so quickly, that the line between "historical" and "live" data management is starting to fade. See for yourself how responsive NitroView is by watching any of the short clips here, or request a live webinar where you can see NitroView operating in a real network. We're so confident that NitroView ESM will impress that we'll even arrange a temporary log-in to our demo systems and let you kick the tires yourself.

Specific SIEM features within NitroView include:

  • Collection of data from multiple 3rd party sources, including firewalls, applications, databases, servers/hosts, IPSs, and more
  • Correlation of all data for the detection of larger threats, to simplify operations
  • Real-time analysis of all data, for Incident Response & forensics
  • Compliance Reporting, including data access requirements of HIPAA, PCI, SOX and others

Database Activity Monitoring & Application Content Inspection

Monitoring access to sensitive information is a necessity for PCI, HIPAA / HITRUST, Sox, and NERC compliance, but how can you be sure that all access is being logged appropriately? How do you know that sensitive data, once retrieved from a database, isn't being misused? The only way to know for sure is actively monitor all database transactions, and then inspect and monitor the contents of application data.

NitroView supports both of these advanced capabilities, using tightly integrates application data monitoring and database activity monitoring appliances: NitroView ADM and NitroView DBM. Alone, these products will help protect sensitive data and enforce privacy concerns; together with NitroView ESM, they provide broad detection of fraud, data loss, and policy violations, and can even help detect APT.

Simply put, the information that allows your business to work: employee records, customer data, credit card information, and other valuable information assets are all stored in one or more databases. Those database are used by applications: web portals, CRM and ERP systems; and a variety of other mission-critical applications. Once accessed legitimately, this information can quickly leak into any number of unintended applications: including email, instant messaging programs, file sharing applications, VoIP calls, and more. The only way to ensure data is being access and used appropriately is to monitor the entire system: from the database to the applications used across the network.

By monitoring, correlating and analyzing database transactions along with the actual contents of applications, it becomes easy to detect data leakage and fraud, such as when a customer service representative types credit card numbers into an Instant Messaging application.

Of course, this data is also the target of most outside attacks, from hackers and other cyber criminals. By correlating database activity and application contents with device logs, events from security devices, vulnerability data, and other SIEM information sources, the entire system becomes a highly sophisticated, content-aware threat detection engine—the only one in its class.

Specific Database Monitoring features within NitroView include:

  • Network- and agent- based monitoring options of all database activity
  • Central device, policy, and configuration management of NitroView DBM
  • The ability to track users from the database across other applications
  • The ability to remediate threats to core data services, through common integration with NitroGuard IPS

Specific Application Content Monitoring features within NitroView include:

  • Auto-detection of sensitive information such as credit cards, and social security numbers
  • The detection of application and protocol anomalies that may indicate threat activity
  • Monitoring of all application use against defined corporate policies
  • The ability to remediate threats, through dynamic blacklists, enforced by NitroGuard IPS

Log Management

NitroView ELM provides tightly integrated Log Management functionality into the award-winning NitroView platform. Unlike other "Log Management + SIEM" solutions, NitroView's performance and scalability allow security information and log management functions to coexist, sharing a common interface. When a security event is generated, the parsed event files are linked directly to the source log file and even to the specific log record — for instant access during the event management and forensic processes. There's no extra step, extra application to launch, or extra time to waste when investigating an incident. NitroView ELM provides flexible onboard or SAN based storage to accomodate any compliance requirement, for any size company—and all stored logs are made available to NitroView's common reporting system, which includes hundreds of pre-built compliance reports for HIPAA, PCI, SOX, NERC-CIP, FISMA, and more.

Specific Log Management features within NitroView ESM include:

  • Universal collection of all log formats
  • Analysis of all logs—alone, or across sources using NitroView ESM
  • Encrypted and Signed storage of log files for compliance
  • Comprehensive Compliance Reporting

Intrusion Prevention: Generating Event and Flow Information

Intrusion prevention systems (IPS) aren't typically associated with SIEMs ... unless the IPS is tightly integrated, and designed to provide as much granular event and flow details as possible. Because any SIEM becomes more capable as more data is available for analysis, IPS devices play a critical role as a primary source of event information. NitroGuard IPS, of course, also collects network flow information, allowing for easy network-to-security information analysis.

An intrusion prevention will either block malicious traffic, or produce an alert on suspect traffic. While the IPS will likely stop a direct attack, it is still a requirement to analyze those attacks. Where did an attack come from? Where is it going? Was a benign event the symptom of some larger threat? If a virus infects a system, what other systems has that host talked to? Where is that system located, physically, on the network? These answers require co-analysis of security events and network flows, which in turn require SIEM capable of collecting both events and flows.

Specific Event Management features within NitroView ESM include:

  • Correlation of events with flows, logs, and other information
  • Central device, policy, and configuration management of NitroGuard IPS
  • The ability to track attack vectors through event/flow correlation
  • Remediation services through the application of IPS configurations, including dynamic blacklists

Network Analysis

In order to apply as much context as possible to event and log information, NitroView ESM builds a full network topology. By discovering devices and hosts, an accurate network map is created, so that all event and flow activity can be given real, locational context. This also allows network awareness for the detection of anomalous behavior on a device or even a specific network link.

Specific Network Analysis features within NitroView ESM include:

  • Collection and analysis of network device, host, and flow information
  • Automatic calculation of baselines for trend analysis & anomaly detection
  • Anomaly-based signatures within NitroGuard IPS
  • Real-time analysis and correlation of flows to other security events

Specifications 

NitroView Enterprise Security Manager Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model           Description                         Events/sec     Report   
speed*    
HDD**    
NS-ELM-XXXX NitroView Enterprise Log Manager (ELM) Integrated Log Management for NitroView ESM & NitroView Receiver
 NS-ESM-X5 NitroView ESM X5 "High Speed" Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for large enterprise networks. 7TB local storage plus 500GB of in-memory storage for etremely high performance. One 3U appliance, plus one 2U Appliance. 40 Million 1 Billion events/sec 7TB +
500GB RAM
 NS-ESM-5750-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for medium to large enterprise networks. 7TB local storage. 3U Appliance. 4 Million 100 Million events/sec 7 TB
 NS-ESM-5510-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions. 3.75TB local storage, 3U appliance 3 Million 50 Million events/sec 3.75 TB
 NS-ESM-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. 2.5TB local storage. 3U appliance. 2 Million 25 Million events/sec 2.5 TB
 NS-ESMRCV-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. Rated for 5,000 events per second and manages up to (5) NitroSecurity devices (IPS, DAM, or APM). 5,000 25 Million events/sec 2.5 TB
 NS-ESMRCV-4245-R NitroView ESM 4000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 1.5 TB local storage. 1U appliance. Rated for 1,000 events per second and manages up to (3) NitroSecurity devices (IPS, DAM, or APM). 1,000 25 Million events/sec 1.5 TB
 NS-NRC-4245 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 18,000 events per second. 18,000 - 1 TB
 NS-NRC-2250 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 15,000 events per second. 15,000 - 1 TB
 NS-NRC-2230 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000 - 1 TB
 NS-NRC-1225 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000 - 500GB
 NS-ESS-5205 NitroView ESM 5000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. Redundant power, 2.5TB local storage. 3U appliance. 150,000 (NitroSecurity devices only) 25 Million events/sec 2.5 TB
 NS-ESS-2230-R NitroView ESM 2000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. 500GB local storage. 1U appliance. 150,000 (NitroSecurity devices only) 15 Million 500GB

* Typical SIEM reports (queries) will complete in a few seconds, even on very large event stores.

** NitroView ESM 5000 models utilize a raid 10 drive configuration, as well as redundant, dedicated drives for OS storage. The number listed above represents the usable capacity for event, log and flow storage.

*** The maximum number of supported devices per ESM is determined by the receiver model(s) used for collection.

Click to see a current list of supported data sources


Related Products

NitroView Database Monitor Specifications

Select a Model for Specifications

Model                  Description      Appliance      Supported DBs      Events/Sec     
NS-DBM-4245-R NitroView DBM 4000, Database Monitor Pack. 1U Appliance good DB2, Oracle, MS SQL, MySQL, SyBase 15,000
NS-DBM-2250-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 10,000
NS-DBM-2230-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 5,000

NitroView Enterprise Log Manager Specifications

Select a Model for Specifications

model              Description      Logs / Sec     
NS-ESMLM-4245-R NitroView ESM / ELM 4000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 1 TB local storage. 1U appliance. 1,000
NS-ESMLM-5205-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. 2,500
NS-ESMLM-5510-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 3.75 TB local storage. 3U appliance. 5,000
NS-ELM-5510-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 3.75 TB local storage. 3U appliance. 35,000
NS-ELM-5205-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 2.5 TB local storage. 3U appliance. 20,000
NS-ELM-4245-R NitroView ELM 4000 Enterprise Log Manager provides Compliant Log Management functions. Supports network / SAN storage options. No local storage. 1U appliance. 40,000
NS-ELM-5750-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 7 TB local storage. 3U appliance. 50,000
NS-NRCLM-4245-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000
NS-NRCLM-2250-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 8,000 events per second. 8,000
NS-NRCLM-2230-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000
NS-LC-2250-R NitroView LogCaster 2000, 1U appliance. Includes (500) LogCaster Agent Licenses. Rated for 10,000 events per second. 10,000
NS-LC-2230-R NitroView LogCaster 2000, 1U appliance. Includes (250) LogCaster Agent Licenses. Rated for 5,000 events per second. 5,000
NS-LC-AGT-200 NitroView LogCaster Large Syslog Device Agent License for quantity 200 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-100 NitroView LogCaster Large Syslog Device Agent License for quantity 100 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-50 NitroView LogCaster Large Syslog Device Agent License for quantity 50 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-25 NitroView LogCaster Large Syslog Device Agent License for quantity 25 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -

NitroGuard IPS Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model                     Description      Throughput      Copper
Ports     
Fiber
Ports     
NS-IPS-5450-R NitroGuard IPS 5000, 3U IPS appliance supporting approximately 4 to 5Gbps & 1.2m connections. Includes redundant power and a bypass NIC. 4-6 Gbps 12x1Gbps 4x10Gbps
NS-IPS-4245-R NitroGuard IPS4000, 1U IPS appliance supporting approximately 2Gbps & 1.5m connections. Includes redundant power and a bypass NIC. 2 Gbps 2, 4, 8 2, 4
NS-IPS-2250-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 750Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 750 Mbps 2, 4, 8 2, 4
NS-IPS-2230-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 500Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 500 Mbps 2, 4, 8 2, 4
NS-IPS-1225 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 250Mbps & 1.2m connections. Includes single power and a bypass NIC. 250 Mbps 2, 4 2, 4
NS-IPS-1160 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 150Mbps & 1.2m connections. Includes single power and bypass NIC. 150 Mbps 2 N/A
NS-IPS-110 NitroGuard IPS 100, Set-Top IPS appliance supporting approximately 50Mbps & 1.2m connections. Includes single power and a 2 port 10/100/1000 Base-TX copper NIC (no bypass). 50 Mbps 2 N/A





 

Search NitroSecurity.com