Lancope Releases New Version of StealthWatch for Enhanced Threat Detection
StealthWatch 6.4 features new levels of network visibility and security intelligence for improved forensics and incident response
ATLANTA, July 9, 2013 – Lancope, Inc., a leader in network visibility and security intelligence, has released the latest version of its StealthWatch® flow-based monitoring system to enable faster, more effective threat detection and incident response. With StealthWatch 6.4, customers can obtain new levels of insight into network and user activity to improve operations and fend off today’s ever-evolving list of advanced attacks.
“The online threats facing governments and enterprises continue to grow – with DDoS, APTs, advanced malware and insider threats all wreaking havoc on corporate networks,” said Mike Potts, president and CEO of Lancope. “With StealthWatch 6.4, we have added several powerful capabilities that provide organizations with enhanced visibility and control over their networks. In particular, our new user-centric monitoring functionality is invaluable for combating insider threats, as well as for improving incident response, forensics and compliance.”
StealthWatch 6.4 boasts new, user-centric monitoring workflows that enable network and security teams to run flow queries and reports based on actual user names versus just IP addresses. Administrators can search on user names, as well as obtain a report outlining a specific person’s network activity – including any anomalous behavior or alarms triggered.
“Diminished IT control over recent years is leading to network grey areas and blind spots,” said Jon Oltsik, senior principal analyst with Enterprise Strategy Group (ESG). “It’s hard to increase the effectiveness of information security when security analysts have an incomplete understanding of what’s going on. Solutions like StealthWatch, combining continuous security monitoring with advanced user identity tracking, are becoming increasingly important for quickly identifying and addressing a wide range of anomalies and threats on the network.”
StealthWatch 6.4 extends Lancope’s detection capabilities for distributed denial-of-service (DDoS) attacks into the application layer with the ability to identify and alarm on slow connection floods for HTTP and HTTPS. StealthWatch also enables organizations to detect the source of volumetric DDoS attacks by alarming on unusually large traffic volumes, providing a multi-pronged approach to thwarting these rising attacks.
As Lancope deepens its relationship with Cisco, it is reflected in StealthWatch 6.4 through tighter and more flexible integration with Cisco’s Identity Services Engine (ISE), ASR/ISR and ASA platforms. Lancope now also consumes user names directly from Cisco ASA NetFlow records, further increasing its identity awareness capabilities. As a key component of the Cisco Cyber Threat Defense Solution and a Registered Developer in the Cisco Developer Network, Lancope also integrates with many other Cisco appliances including the NGA.
StealthWatch collects and analyzes NetFlow and other flow data from existing infrastructure to dramatically improve network security and reduce enterprise risk. In addition to the new features described above, version 6.4 also includes multiple usability and performance enhancements as detailed here. Version 6.4 is currently available with entry-level system pricing beginning at U.S. domestic $71,495. For more information on StealthWatch for improved network visibility and security, go to: http://www.lancope.com/solutions/.
Lancope, Inc. is a leading provider of network visibility and security intelligence to defend enterprises against today’s top threats. By collecting and analyzing NetFlow, IPFIX and other types of flow data, Lancope’s StealthWatch® System helps organizations quickly detect a wide range of attacks from APTs and DDoS to zero-day malware and insider threats. Through pervasive insight across distributed networks, including mobile, identity and application awareness, Lancope accelerates incident response, improves forensic investigations and reduces enterprise risk. Lancope’s security capabilities are continuously enhanced with threat intelligence from the StealthWatch Labs research team. For more information, visit www.lancope.com.
# # #
©2013 Lancope, Inc. All rights reserved. Lancope, StealthWatch, and other trademarks are registered or unregistered trademarks of Lancope, Inc. All other trademarks are properties of their respective owners.
Jody Ma Kissling
Lesley Sullivan/Kendra Dorr