Part three of a four part Use Case series

Use Case 3: Testing security appliances with real world data with SYNESIS

Not a day goes by where you don’t see another security breach, zero-day exploit, or some malicious software wreaks havoc to users and organizations.  Just recently the WannaCry cyberattack just hit computer systems worldwide.  Some vulnerabilities don’t even make it to the headlines and aren’t discovered for weeks or even months?  So what does that tell us?  Current security tools don’t know what they don’t know!  That’s a big dilemma for security vendors and their customers.  How can security vendors, their appliance products, and teams:

  • Analyze security exploits that have already occurred if their products failed to catch them in the first place?
  • Insure future product releases are regression tested using real world data?

With today’s high traffic rates, security appliances often can’t perform real time analysis fast enough.  Typical IPS analysis performance is typically less than 10Gbps even when running at the lowest resource intensive security functions.  When organizations are faced with multiples of 10Gbps aggregated traffic even the highest rated security appliances can’t analyze fast enough in real time.   The result, missed data…missed analysis.  An organization can load balance traffic between multiple security appliances of the same type but that can prove costly and it still doesn’t guarantee all traffic is analyzed at all times such as during microburst conditions.  This adds extra pressure on security vendors….how can they analyze missed data and insure future releases are tested against real world data.

With SYNESIS, real world data can be captured even at the highest ethernet rates.  SYNESIS Capture and Replay allows network security appliances to re-analyze missed data or retest after a patch is available.  This guarantees complete packet data is always available for post analysis.  With SYNESIS’ Three Rs we can:

RECORD – External traffic is duplicated into SYNESIS for long term storage during normal business hours.  During high traffic conditions a security appliance may not analyze fast enough given the sheer volume of traffic or, in the worst case, due to a catastrophic failure.  However, all packet data is mirrored with the use of taps/network packet brokers to a SYNESIS Portable or Rackmount appliance for Recording.  SNMP Traps may also be sent by the security appliance to lock the packet data in SYNESIS for a specific time range to prevent it from being over written.  That data will then be available to the security appliance for post analysis in addition to manual analysis using a packet decoder (i.e. Wireshark).

REPLAY to REPLICATE – Security vendors may also take the recorded traffic containing the suspect data back into their lab for further packet analysis in pursuit of a code fix by security engineers.  The data may be Replayed to Replicate the conditions that caused the failures in a more controlled environment with the security appliance as the device under test.  The data may also be replayed during automated regression tests by QA teams.

Click here for more information on SYNESIS!

Click here for Part 1: “The Three Rs: Record, Replay, Replicate — Replicating customer issues in the lab”

Click here for Part 2: “The Three Rs: Record, Replay, Replicate — Isolating a video streaming quality issue using SYNESIS”

Be on the lookout for Part 4 of our four part series: “The Three Rs: Record,Replay,Replicate”