| Behavioral Threat Prevention |
|
|
Intruder Profiling & Trusted System ManagementInternal and external device behaviors are continuously tracked and profiled in Arbitrator's IP Profiler. As systems violate security rules they are automatically categorized as suspicious or malicious, depending on the number and severity of security policies they violate. This real-time behavior profiling allows Arbitrator to respond differently based on the trustworthiness of the device. Real-time Threat DetectionSuspicious or threatening behaviors are identified by Arbitrator's real-time Correlation Engine using a combination of event log, flow information, and real-time environmental data. As threats occur they are easily visualized in Arbitrator's Threat Analysis dashboards, allowing you to watch threats evolve before they become critical. Additionally, new threat rules can easily be added using Arbitrator's Rule Wizard, or you can simply download rule "bundles" from the layerX Storefront. Proactive Threat DefenseThe ability to detect threats is only valuable if the system can proactively respond to threatening behaviors to protect your critical assets. As threats are identified Arbitrator's Response Engine automatically engages to mitigate threats proactively across your network - using your existing protection appliances. With Arbitrator in your network, threatening entities are automatically blocked, redirected, or quarantined, based on their behavior, to ensure your assets are protected. Real-time Threat ExchangeArbitrator's real-time threat exchange service, Threat-share™, allows you to share and receive real-time blacklist updates with layerX. When you activate Threat-share, real-time blacklisted IP addresses are added to your IP Profiler - giving you real-time threat visibility beyond the perimeter of your network. Additionally, you can have Threat-share information automatically added to correlation and response rules - allowing you to set up perimeter blocking rules for malicious systems before they reach your network. We Also RecommendIf you are interested in the Behavioral Threat Prevention Modules for Arbitrator™ you may also be interested in the Security Information Management (SIM) Module, which adds complete event visibility through the collection of multiple types of data, and the perfect balance of power, flexibility, and ease of use through our integrated rule management capabilities. |