Adaptive DarkNet
Combines Customer Premise Device and Vendor Service
The Adaptive DarkNet service combines a specific, on-premise device with a multi-point network service provided by the vendor in an attempt to prevent components of the local network from unwittingly participating in attacks on third parties. The vendor states that the platform can be implemented either independently, or as a complement to existing IPS/IDS schemes.
The MainNerve service is facilitated through its network of multiple data collection points from across the Internet. These collection points, which include flow analyzers, and other darknets, among others, provide real-time network behavior data to MainNerve, which in turn correlates the data to identify active threats and attacker control channels and targets. Such information is then transmitted in real-time to the customer premise equipment, which in turn adaptively modifies its configuration and instructs the customer's network to send all activity defined as malicious (based on the exact source IP address of attackers and not requiring specific signatures or protocol usages) to the premise equipment, instead of its intended recipient. These transactions are then blocked and logged by the premise device for later review by a system administrator. The platform also captures worms scanning network regions.
The premise device, the Interrogator AD (from Packet Interrogation) is a 1U device that is installed at the network gateway; it requires that your router be BGP-capable and that it contain 2 100 Mbps interfaces.
Contact MainNerve for further information.
product submission by EITPlanet Staff
E-Mail this page to a colleague
send info about Adaptive DarkNet

Suggest a link
for the Adaptive DarkNet fact sheet