For more press information contact: Abigail Johnson/Paul Michelson Roeder-Johnson Corporation (650) 802-1850 http://email.roeder-johnson.com |
For more customer information contact: cPacket Networks Mountain View, CA +1 (650) 969-9500 FAX: +1 (650) 969-4900 info@cpacket.com |
CPACKET'S 10 GIGABIT CFLOW APPLIANCE BENEFITS HIGH-PERFORMANCE NETWORK INTRUSION DETECTION SYSTEM AT LAWRENCE BERKELEY NATIONAL LABS
1U Box Frontends First Scalable, Stateful NIDS on Commodity PC Cluster
MOUNTAIN VIEW, CA – OCTOBER 15, 2008 – cPacket Networks revealed today that their previously-unannounced cFlow appliance is serving as the load-balancing frontend to a powerful, high-speed network intrusion detection system (NIDS) implemented at Lawrence Berkeley National Laboratory (Berkeley Lab), that uses clusters of commodity hardware for analysis. The cFlow splits a heterogeneous packet stream of 10 gigabits per second into multiple, load-balanced subsets that meet specific criteria – for example, all the interrelated packets of specific HTTP sessions – and redirects each such subset to a different destination in the cluster.
In the Lawrence Berkeley National Laboratory intrusion detection system, each such subset is redirected to one of the inexpensive commodity PCs in a cluster, which performs security analysis using an open-source analysis engine. The PCs communicate with a management PC to provide the fine-grained correlation necessary for high-quality operational security. The system is inherently scalable, easy to maintain, and can be made extremely fault tolerant with simple hot backups.