Araknos
AkabSensor - Traffic Monitoring

Akab architecture is based on AkabSensors - a family of appliances for management of network data both directly acquired or received from other network appliances/applications.

AkabSensors have crucial role in system monitoring as they provide data to various Anomaly Detection and Event Correlation algorithms run in other higher level appliances.

The AkabSensor family consists of various specialized appliances divided in two groups, Security Management and Network Management appliances: security audit (AS-SA), intrusion detection (AS-ID), bandwidth management (AS-BM), traffic monitoring (AS-TM), and log server (AS-LS).


All AkabSensor appliances for Network Management (BM, TM and LS) are available in stand-alone configuration as well.


 

Akab Sensor TM

 

AkabSensor Traffic Monitoring (referred shortly as AS-TM) is a network traffic monitoring appliance that incorporates functions of acquisition, storage, visualization and reporting of the network traffic data.

Features

  • data detection (Policy-based and Anomaly Detection)

  • data storage for farther statistical or forensic analysis

  • Web-based GUI data visualization and reporting

Moreover AS-TM offers the possibility to retrieve from Windows Active Directory/LDAP users, user groups and containers responsible for the network traffic.

 

Data Acquisition

AS-TM acquire network traffic information from different data sources:

  • “sniffing”

  • Netflow

  • SFlow


Data Storage

Network traffic data is stored in two data formats:

  • statistically aggregated

  • DB/SQL DB


Data Visualization

Visualization of AS-TM data is structured in various reports that can be accessed through a Web-based GUI and be farther customised and filtered according to different temporal and traffic criteria.


Configurable Reports

List of most active protocols, services, users and applications


Reports

Real time and history reports on network traffic are available in HTML, text, CVS and PDF formats.


High Availability

Every AS-TM appliance is supplied with a secondary twin stand-by appliance that becomes active if, for any reason, the primary appliance is not able to function properly (fail-over).

 

Technical Documentation