Duxbury Networking has released SecureWatch, a purpose-designed high performance security software solution from its principal, TopLayer Networks.
Designed to meet the demands of gigabit speed networks, SecureWatch is a scalable data acquisition software application primed to capture richly detailed telemetry regarding security application data flows and store it in a database repository, or to relay filtered data to a downstream system.
Examples include the observed User ID name captured from an authentication sequence, the DNS name of the host workstation, or the source domain of any specified data flow.
Running on the Wintel platform, SecureWatch is said to leverage the multi-processor, multi-thread features of advanced hardware systems for maximum performance under heavy loads.
According to Duxbury Networking chief technology officer, Graham Vorster, the software solution is able to anticipate the capacity demands of large enterprises, service providers and carrier class networks.
He explains that a key component of the SecureWatch data acquisition solution is the SecureWatch Server, which facilitates communication with data producers, formulates the definition of data outputs and formats to various agent modules. It also facilitates the management of the system.
The SecureWatch Server comes standard with Syslog and Microsoft Access data agents. The Syslog agent includes a format definition for Web Trends WELF format.
SecureWatch is also an essential part of the Check Point OPSEC certified Top Layer DDoS Attack Mitigation solution. SecureWatch takes DDoS forensic data, formats it to the specifications of the Check Point Event Logging API (ELA), and conveys the telemetry in real-time to the Check Point Management Console for consolidation with other security event data.
"This allows users to have a single and consolidated security event log in which the actions of anyone attempting a security breach are documented and registered," explains Vorster.
"Furthermore, attacks and aberrant behaviour that would normally stay `under the radar`, and not cross the trigger points of the firewall, are captured and stored for trend analysis," he adds.
Editorial contacts

