|
Network VCR
Iris records
communication data traveling across your network and plays it back
either in real time or at a later time.
Packet
Manipulation and Forging Capabilities
Iris provides
the ability to create custom packets to send across the network.
Extensive
Filtering Options
Iris allows you
to capture specific data through packet filters based on hardware
or protocol layers, keywords, MAC or IP addresses, source and
destination port, custom data and packet size.
Post-Capture
Data Analysis
Iris' Data
Miner can process any amount of data, from a single traffic file
to large amounts of captured data, at one time. This feature is
available for comprehensive analysis of saved traffic.
Protocol
Decoding
Iris organizes
captured packets and categorizes them by protocol such as HTTP,
PPoE, and SNMP, providing a list of all web-browsing sessions, all
email grouped by incoming and outgoing, and more.
Powerful
Sniffing and Spoofing Engine
Iris can handle
as much traffic as your network generates and still write logs and
decode traffic in real time. The Iris engine can handle up to
9,000 packets per second.
Scheduling
Function
Iris is easily
configured to automatically run and capture packets in specific
time frames.
Alerting
Capabilities
Iris' Guard
module monitors all connections to the local machine and can alert
when a specific connection is detected.
Reconstruct TCP
Sessions
Iris support
several Protocol Decoders through an open plugin based
architecture, including: ARP, CIFS, DNS, Ethernet II, 802.3,
802.2, ICMP, IP, TCP, UDP, Novell NetBIOS (IPX), SAP (IPX), RIPX (IPX),
BCAST (IPX), NBDGM, NBNS, NBSS, NetBIOS, SMTP, AOL AIM, MSN
Messenger, BOOTP/DHCP, RARP, POP3, SMTP, LCP (Link Control
Protocol) (PPP), PAP (Password Authentication Protocol (PPP),
PPPoE (PPP over Ethernet) (PPP), SMB, NNTP.
Statistics and
Reports
Iris provides
DNS names and comprehensive statistical measurements. The metrics
can be viewed in an assortment of graphical formats (e.g. pie
charts, bar graphs, etc.) and include:
- Protocol
Distribution Stats
Reports network
usage based on MAC, IP and IPX layer protocols.
- Top
Host Statistics
Provides an
analysis of the IP Layer traffic statistics collected for each
host in real time and is ordered by the
most
"talkative" hosts.
- Size
Distribution Statistics
Displays the
number of packets with sizes in six different ranges.
- Bandwidth
Usage
Charts the
number of packets per second and bytes per second flowing across
the network in real time.
- Traffic
Reports
Complete
traffic data that can be viewed in a browser, saved, printed, or
copied into another program.
Data
Reconstruction
Iris takes raw
data in packets and turns it into complete HTTP, SMTP and POP3
sessions in their original format. The following are some of the
protocols Iris reconstructs:
- Outgoing
and incoming email messages
The text of the
message is readable as well as the subject and recipient. Iris
will launch an email client to open the message, as well as any
attachments, exactly as they were sent.
- Web
browsing sessions
Reconstruction
of HTML pages in their original format.
- Instant
messenger exchanges
Iris will
reconstruct all IM communications from both sides of the
conversation.
- Non-encrypted
web-based email
- FTP
transfers
|