Locating Malware Infections
Despite having antivirus and other measures, malware finds ways to creep into the company. They arrive via
- phishing attacks
- traveling laptops
- employee VPN sessions
- employee downloads, bloatware
- P2P networks
- instant messengers
- file repositories
- USB memory-keys
- ...
Malware tend to be part of botnets, which receive commands from the black-hat organizations and are commonly used in spamming, identity theft, etc. Other potential uses of botnets and other malware can be espionage, data theft, cyber-terrorism, attack on infrastructure, etc.
A drawback of current anti-malware products is that they cannot detect malware which hides by mutation and by rapid propagation before signatures are created. Such zero-day issues can be detected by nLive. By detecting abnormal traffic such as unusual ARP, unusual connections and suspicious traffic, nLive can often point to machines infected by malware, even when existing anti-malware products failed to detect them.
nLive is designed to detect abnormal traffic from malware-related network activities. It has been the experience of several users of nLive to detect malware-infected hosts within hours of installing nLive. One or more of the 45 detectors provided with nLive triggers when various kinds of abnormal traffic originates from a host.
Example Solutions
The following are basic write ups on how to solve certain network problems using nLive. More detailed step by spet procedures are given towards teh end of the user manual, which is available in the Learning Center.Traffic visibility
Network Traffic VisualizationReal Time Traffic Analysis
Locating Network and Department Top Talkers
Network Applications and Ports
Network bandwidth Congestion
Traffic Reporting
Network Security IssuesNetwork Traffic Trend Analysis
Network Traffic Search and Forensic Analysis
Executive Reporting of Network Traffic
Regulatory compliance
Bandwidth Monitoring and Utilization
Locating Bandwidth AbusersApplication Bandwidth Usage
Wide Area Network Bandwidth
Local Area Network Bandwidth
Abnormal Traffic and Anomaly Detection
Abnormal Traffic DeterminationEmployee Misuse Detection
Locating Malware Infections
Network Fault Locating
Data Leak or Theft