About Us  |  Services  | Recruitment  |  Advertise  | Contact

 

Computer Network Defence Ltd

IDS & IPS Products
Network IPS
Attack Mitigation Systems
Network IDS
Target IDS
Host IPS
Host IDS
Application IDS
Wireless IDS
Honeypots
File Integrity Checkers
Network Taps
IDS Balancers
Switch Port Mirroring
IDS Terms A-H
IDS Terms I-Z
Deploying IDS Guide
Security Info Managers
Scanning Products
VPN & Firewall Products
Forensics Solutions
Content Protection
Training Courses
Raw Packets
Bug Sweeping / TSCM
Miscellaneous
Services


Attack Mitigation Systems
The main difference between NIPS and Mitigators would be Mitigators are designed to do one specific job - detect and mitigate against DOS/DDOS attacks and bilateral effects of worm activity and are largely rate based. NIPS are content based, designed to detect malicious traffic and drop the packet/stream. NIPS are not always necessarily good at mitigating DOS/DDOS attacks. Mitigators generally do not have the signature coverage to provide good NIPS functionality. NIPS are like IDS but in-line. Mitigators are like firewalls but designed to detect and prevent DOS attacks rather than enforce policy.  There is some overlap between Attack Mitigation System technologies and Network Intrusion Prevention Systems therefore I'd strongly suggest looking at the Network Intrusion Prevention System Page

Click Here For a Great DDOS Article



 

DefensePro

Appliance

Radware Ltd.

http://www.radware.com/content/products/dp/default.asp?ref=BDPSecurityWizardry

DefensePro features inline security switching and accelerated, stateful, deep-packet inspection - using Radware’s StringMatch Hardware Engine™ – to bi-directionally scan and protect all network traffic against application level attacks.
DefensePro Application Security immediately isolates attacks by dynamically managing bandwidth to stop propagation across users and resources while ensuring the complete continuity and performance of all secure traffic to proactively control impact and limit damage. DefensePro intercepts over 1,500 malicious signatures, hidden worms and viruses, blocking application attacks at a of 3-Gigabits/Sec. Identifying and mitigating protocol and traffic anomalies in real-time, DefensePro prevents DoS/DDoS and SYN floods, safeguarding against all illicit traffic patterns and hacking

COMMERCIAL

Information Updated:13 Nov 2004

Click Here To Go To The Top Of The Page

Riverhead

Appliance Riverhead Networks http://www.riverhead.com/pr/index.html
Riverhead offers two different products: the Riverhead Detector, which detects DDoS, worm and other attacks and reports on their characteristics; and the Riverhead Guard, which performs the per-flow level attack analysis, identification and mitigation services that block attack traffic. Two different product families are available:

COMMERCIAL

Information Updated:30 Jan 2004


Attack Mitigator

Appliance

Top Layer Networks

http://www.toplayer.com/content/products/
intrusion_detection/attack_mitigator.jsp

Top Layer's Attack Mitigator™ IPS is a family of high performance, ASIC-based intrusion prevention solutions with intelligent blocking and control against the most prevalent cyber attacks. Hybrid attacks such as HTTP worms, DoS / DDoS attacks, protocol and traffic anomalies, IP spoofing, SYN flood attacks, and more, are accurately detected, and stopped in real-time. The Attack Mitigator IPS allows the network security administrator full control in selecting how the device will respond to detected attacks. Precise but flexible actions against blocking malicious and suspicious traffic include monitoring, alerting, limiting and blocking. Attack Mitigator IPS offers 100 megabit through multi-gigabit solutions for maximum performance.

COMMERCIAL

Information Updated: 13 Nov 2004

Click Here To Go To The Top Of The Page

StealthWatch

Appliance

Lanscope

http://www.lancope.com/XFRM.asp?RTN=Data/G1&XML=products.xml&XSL=products.xsl

Ensuring a secure network, StealthWatch defends against both known and unknown threats from internal and external sources. By correlating suspicious activity across the network and detecting real time deviations from established profiles and security policies, StealthWatch rapidly identifies, prioritizes and contains malicious network and host behavior.
By monitoring and profiling network servers, workstations and devices in real time, StealthWatch enables you to establish baselines of typical activity in order to identify and respond to misuse. This detailed knowledge of host communications assists in firewall planning and pinpoints unauthorized or excessive application usage to reduce vulnerabilities and optimize network performance.
StealthWatch maintains an archived database of network flow logs and creates graphical reports of network activity for in- depth analysis. Armed with this forensic data, you can easily trace the source and impact of network security events. On- going analysis also supports remediation, response and other proactive prevention efforts by providing detailed information about internal and external communications across the network.

Commercial

Information Updated:20 Jan 2004

Click Here To Go To The Top Of The Page

DeepNines Security Edge System (SES)

Appliance

DeepNines Inc.

http://www.deepnines.com/ips.php

Eliminate Unwanted Traffic with DeepNines’ Security Edge System (SES)

DeepNines increases network security, productivity and compliance with the Security Edge System – the industry’s first intrusion prevention system (IPS) to allow only good traffic into the network.

The DeepNines Security Edge System (SES) stops malicious Internet attacks before they impact your network. Designed as the first line of defense for your network, SES prevents the security breaches that decrease network availability and sap your IT resources.

Guard Against Unwanted TrafficThe SES is an inline device designed to protect against:
* Signature-based attacks (over 8,000 rules)
* Protocol anomaly attacks
* Behavioral anomaly attacks (22 different heuristics)
* Denial of Service attacks (DoS, DDoS)
* Self-propagating attacks
* Spyware
* Phishing attacks
* Worms and viruses

Commercial

Information Updated: 06 Sep 2007


CHARM

Appliance

Webscreen Technology Limited

http://www.webscreen-technology.com/

Webscreen Technology Inc. is proud to present the Webscreen family of Network Security products. Specifically tuned to detect and prevent Denial of Service (DoS) and Distributed Denial of Service (DDoS), Webscreen makes use of a sophisticated heuristic algorithm to separate malicious from legitimate traffic. Webscreen customers experience very high levels of network accessibility even under the most vicious attack, and experience enhanced performance of other network components.

Commercial

Information Updated: 29 Jan 2004

Click Here To Go To The Top Of The Page

Last page update:  06 Sep 2007

Computer Network Defence Ltd
Information Security Consultancy and Recruiting
enquiries@securitywizardry.com 

Copyright © 2004 Computer Network Defence Ltd. All Rights Reserved.

PO Box 2680, Corsham, Wiltshire, SN13 0ZR, UK
Phone       0870 3219014
International +44 (0) 1225 811806