NetQoS® Inc. has launched a network behavior analysis (NBA) solution called Anomaly Detection, that leverages the company's strength in NetFlow-based collection and analysis. Being integrated into the NetQoS Performance Center Anomaly Detection can enable faster troubleshooting by showing how anomalies impact network and application performance across an organization.
Network engineers and operations managers can now for the first time identify and troubleshoot network behavior anomalies from within one network performance management product suite. NetQoS Anomaly Detection is an early warning system that continuously monitors traffic and performance details from network hosts and alerts network engineers to abnormal patterns that could impact application performance and delivery. Anomaly Detection leverages the robust NetFlow collection architecture of NetQoS ReporterAnalyzer™ to identify irregular traffic patterns across the network infrastructure in real time and pinpoint the causes, such as misconfigured devices, unexpected or unauthorized user activity, or unauthorized new equipment and applications. In addition, Anomaly Detection provides the relevant host IP address, router, and interface.
The details from Anomaly Detection can then be plugged directly into ReporterAnalyzer through the NetQoS Performance Center interface for faster network troubleshooting. Network engineers can then use the newly expanded Flow Forensics capabilities in ReporterAnalyzer version 8 to drill into the flow records, showing hosts and conversations, to troubleshoot the anomaly. The enhanced Flow Forensics capabilities make it easier to troubleshoot by going from an enterprise summary of 100 percent of network traffic down to detailed flow forensics with just a few mouse clicks.
Steve Harriman, vice president of marketing for NetQoS, said: "The NetQoS Anomaly Detection capability is significant because it monitors every traffic flow using the industry's most widely deployed enterprise-class NetFlow-based monitoring solution and provides an alert every time unusual activity occurs. Just as important is the integration with the NetQoS Performance Center, which allows customers to go from that initial alert to substantive troubleshooting in just a few mouse clicks and is a key enabler for proactive management of application delivery problems."