NetFlow
ADMs customised network flow engine is the most reliable tool to identify and trace attacks in real time. It performs multiple functions such as monitoring the network, network planning, anomaly tracing, and helps to establish and analyse network traffic trends. Most attackers and hackers probe the security of an organisation before launching an attack to seek the vulnerabilities in the security that they can exploit to their advantage. The netflow engine identifies any such probing attempts that seek an entry into the network.

Netflow Analysis
The basic function of the netflow engine is netflow analysis that generates the critical information such as source and destination IP, source and destination ports and internet protocol usage of the malicious logs. However, the attackers are smart enough to snoop the source IP addresses to lose their trail. The netflow engine integrates with the advanced and intelligent correlation modules of RSEM and utilise the intelligence feeds of the CNAM engine and collaborates and correlates similar instances of network probing elsewhere and arrives at inferences to trace the attacker in real time.


