McAfeeWorks.com is a McAfee SecurityAlliance Premier Partner

McAfee - Antivirus Software and Intrusion Prevention SolutionsMcAfee Network Threat Response

Deconstruct, analyze, and respond to threats inside your network

McAfee Network Threat Response

McAfee Products
McAfee Network Threat Response A50 Hardware
McAfee Network Threat Response A50 Appliance
Supports 4 1-Gigabit Ethernet interfaces and delivers up to 500Mbps traffic analysis performance. One AC power supply standard.
#NTR-A050-BA
List Price: $30,000.00
Our Price: $25,500.00
McAfee Network Threat Response A100 Hardware
McAfee Network Threat Response A100 Appliance
Supports 4 1-Gigabit Ethernet interfaces and delivers up to 1Gbps traffic analysis performance. Includes RAID-1 for higher performance.
#NTR-A100-BA
List Price: $70,000.00
Our Price: $59,500.00
McAfee Network Threat Response A200 Hardware
McAfee Network Threat Response A200 Appliance
Supports 8 1-Gigabit Ethernet interfaces and delivers up to 2Gbps traffic analysis performance. Includes RAID 1+0 for higher performance
#NTR-A200-BA
List Price: $85,000.00
Our Price: $72,250.00

More pricing below, click here

McAfee Network Threat Response Overview:

Automatically analyze the threats attempting to spread across your network. McAfee Network Threat Response (NTR) enables security analysts to dig deep into threats and construct forensic analysis to effectively characterize and respond to malware in the way that’s most effective for your organization. McAfee NTR is a perfect complement to McAfee Network Security Platform, our network intrusion prevention solution, and also delivers streamlined integration with McAfee Firewall Enterprise.

Key Advantages:  
Unique to your network
  • Finds new behaviors unique to your network, activity you have never seen before, accelerating your analysis and response against targeted attacks.
  • Shows you confirmed attacks, malware payloads and BOT distribution websites

Reduce analyst-to-sensor ratio

  • The ability to analyze data quickly leads to the need for fewer SOC / CERT level 1 and 2 analysts
  • Ability to add new modules for specific emerging threats: java script messaging, shell code detection, etc.

Reduce time-to-respond

  • Finds malware and automatically sends info to McAfee’s host protection
  • Prevent by pushing out updated .DAT file within minutes or import into NSP
Implements a process
  • Process framework for determination of false negatives
  • Cross correlation
  • Tertiary detection (decoy)

More value through integration

  • Compliments McAfee Network Security Platform (IntruShield) by detecting and analyzing the unknowns
  • Integrates with McAfee host-based malware protection to provide up-to-date attack signatures

Reliable, network-class platforms; next-generation network protection

  • Performance from 50 Mbps up to 10 Gbps

Ease of deployment

  • Installing the Network Threat Response appliance takes only a few minutes.


Description:

McAfee Network Threat Response (NTR) is an out-of-band appliance that captures, deconstructs, and analyzes malware specific to your own network. McAfee NTR is a powerful tool for security analysts. It automatically identifies malware targeting internal network vulnerabilities, and instantly captures and analyzes it to aid remediation. The McAfee NTR appliance sits inside your network and streamlines the forensic threat analysis process with the following features:

  • Find: McAfee NTR finds malware activity in real time and even decodes polymorphic encoders. The Network Threat Response Control Center dashboard provides full visibility into discovered malware.
  • Create: McAfee NTR creates analysis to help you better understand the malware, how it is attacking your network, and its payload.
  • Prevent: McAfee NTR helps you update your security posture by capturing malware and automatically sending samples to McAfee Artemis Technology, McAfee’s host-based malware protection technology. Updated .DAT files are then pushed out to all protected systems within minutes. These shared signatures bring the full power of McAfee Labs research to McAfee NTR. McAfee NTR offers exceptional integration with McAfee Firewall Enterprise.

Benefits and Features:

Benefits:

  • Give security analysts a powerful forensic tool
    Get deep visibility into the threat context inside your network. McAfee Network Threat Response (NTR) provides the specific data you need to develop security strategies and protect your network from malicious activity and targeted attacks unique to your environment. For example, McAfee NTR can examine a series of packets to characterize an attack, discover malware payloads embedded inside an otherwise-innocuous PDF file, analyze payloads, and even re-create the series of packets that attempted to obfuscate the threat.

  • Characterize unknown threats
    Find new network activity and new behaviors unique to your network to accelerate malware analysis and threat response. McAfee NTR’s network-based technology focuses on identifying, collecting, reverse engineering, and labeling malware and bots. It provides real-time capture and analysis of malware and threats inside your network, and determines what occurs after the initial labeling or characterization of an attack. For example, if you’re already using intrusion prevention, your IPS may block a threat by dropping the traffic, but it has limited ability to go back and analyze the threat that was blocked (dropped).

  • Automate the response process
    Reduce time spent sifting through thousands of threat alerts. McAfee NTR shows you confirmed attacks. All network traffic is labeled. Encoded data is decoded. By using a unique embedded data-coupling process, McAfee NTR confirms the appearance of vulnerabilities and exploit attempts. Other analysis solutions may help track threats back to their original sources, but only McAfee NTR dissects the threat in near real time to understand how a targeted attack specific to your network is entering the network, how it is operating, and how it is trying to spread. When NTR discovers both a vulnerability and a means to exploit it in the same stream, it confirms the attack.

  • Reduce the sensor-to-analyst ratio
    Automate tedious manual examinations, enabling experienced security analysts to focus on new, abnormal, and unique network activity. By providing metadata signatures with built-in correlation elements, such as data coupling, McAfee NTR streamlines security event detection, validation, and reporting.

Features:

  • Instant threat response
    Identify malware using network exploits to move on your internal network. McAfee Network Threat Response captures malware for analysis and response. This stream-based solution rapidly decodes payloads, intercepts and downloads malware, and provides detailed analysis. It checks packet headers for abnormalities and can even replay the attack, if desired. For example, McAfee NTR can identify that a PDF file that appears innocuous actually contains portions of malware that are part of a sophisticated, obfuscated attack.

  • Unique signature database to block attacks
    Trust a large signature database, as well as templates, to stop attacks. The SNORT-compatible malware signature database contains more than 18,800 signatures, and 200 new signatures are added each month. McAfee NTR helps create new signatures to block future attacks. You can even add your own SNORT-compatible signatures.

  • Easy integration with McAfee network security solutions
    Get complete protection against malware. McAfee NTR typically works in conjunction with an enforcement appliance like McAfee Network Security Platform (NSP/IntruShield) or McAfee Firewall Enterprise (Sidewinder). New malware is captured and sent to McAfee Artemis Technology to prevent further infection. When McAfee NTR is deployed in conjunction with an inline IPS system (NSP) and a firewall (FW), it provides complete attack coverage for malware unique to your network.

  • Streamlined web-based management
    Reduce overhead and save time with simple, centralized management. The McAfee Network Threat Response Control Center is a web-based management console that manages multiple NTR sensor appliances. Control Center is also installed on each sensor appliance for single-box evaluation.

Solutions:

The missing link in complete network security protection.

McAfee® Network Threat Response discovers zero-day malware that will use or is using network exploits to attack your network, and then automatically captures that malware for analysis and response. Install the appliances and immediately start detecting malware unique to your internal network. Get full visibility of discovered malware through the Network Threat Response Control Center dashboard. Deploy with McAfee Network Security Platform and McAfee Firewall Enterprise to provide multi-pass analysis of embedded network threats. Integration with McAfee host-based malware technology automatically keeps your threat database up-to-date.

Analyst Tool
McAfee Network Threat Response (NTR) is designed as a security analyst tool. It focuses on two metrics to increase the efficiency of security operation center (SOC) operations; therefore reducing cost. These metrics are: 1) increasing the sensor-to-analyst ratio, and 2) reducing the time-to-respond.

Sensor-to-analyst ratio
The first metric focuses on increasing the sensor-to-analyst ratio. Doing so increases the amount of data that an analyst can handle. By providing meta-data signatures that have correlation elements (data coupling) built into them, the system works as a whole, detecting, validating and reporting events. This allows mundane analysis a means to be done in an automated fashion, and allowing experienced analysts to focus on new and abnormal activity.

Time-to-respond
The second metric focuses on reducing the time-to-respond. By validating data, NTR collects information that is part of the response process, in an automated fashion. In one sense, it performs expert analysis in an automated way supplementing weaker staff. More importantly, it provides stronger information from an event allowing knowledgeable staff necessary data they can act on, as opposed to taking time to collect it.

Reducing response time is a three step process:

  1. Find
  2. Create
  3. Prevent

First, NTR finds malware activity in real-time. It even decodes polymorphic encoders if necessary.

Second, NTR creates analysis information that can be used to better understand the malware, its attack vectors, and its payload.

Third, NTR helps prevent further attacks by capturing the malware and automatically sending samples to McAfee’s host-based malware protection technology called McAfee Artemis Technology. Updated .DAT files are then pushed out to all the protected systems within minutes.

The same signatures used to sort through malware are used by the McAfee Firewall Enterprise appliance IPS subscription to block intruders. These shared signatures are updated constantly, with dozens being added or modified daily.

Implements a process
NTR is a framework that allows automated capability associated with categorization and discovery, allowing next step processes to occur in near-real time. This process framework helps you determine false negatives, false positives, and actual confirmed attacks.

Data reduction
Finding the ―needles in the haystacks‖ requires data analysis to reduce the large datasets. For example:

  • Raw Alarm Data - 40,000 Alarms
  • Session Correlation - 20,000 Sessions
  • Source Grouping - 2,000 Source-destination pairing
  • Behavioral Grouping - 230 Behaviors or possible attacks
  • Confirmed Attacks - 15 Behaviors confirmed with 70 sources

What you don’t know can hurt you
McAfee Network Threat Response provides visibility inside your own network that others do not see. It protects your network from malicious activity unique to your environment, especially targeted attacks.

There are two categories of attacks: those you know and those you do not know. IPS systems block networks from known attacks. This includes zero-day, Denial of Service (DoS), and encrypted attacks as well as threats like spyware, Voice-over-IP (VoIP) vulnerabilities, botnets, malware, phishing, network worms, Trojans, and peer-to-peer applications. These known attack signatures are created from attack collection systems located globally. They represent the most likely or common attacks in the network, but certainly not all of them.

A system is needed to identify and block the unknown and new attacks. Such a system would greatly assist a first level analyst at a SOC to identify these unknown threats more quickly and with more accuracy. This is the function of the McAfee Network Threat Response sensor appliances.

McAfee Network Threat Response’s strength is its ability to determine what occurs after the initial labeling of an attack. By comprehending the attack, the system can perform actions to prevent further associated attacks and aid the system in recovering from the detected attack.

McAfee Network Threat Response Circle

When deployed in conjunction with an in-line IPS system (NSP) and a firewall (FW), it provides complete attack coverage for malware unique to your network.

McAfee Network Threat Response detects and monitors unknown threats. It performs a gap analysis for what other network-based products are not seeing. It does this by labeling traffic, filtering out the ―knowns‖, and then rebuilding the attack scenario when a payload is detected on a vulnerable system.

McAfee Network Threat Response Diagram

Capturing malware
The McAfee Network Threat Response sensor appliances scan your organization’s network traffic looking for new malware payloads and bot distribution websites, including DNS fast flux, which eliminates the changing IP address problem of sophisticated attacks.

This network-based technology focuses on identification, collection, reverse engineering and labeling of malware and bots. It is similar to the McAfee host-based malware protection (McAfee Artemis Technology), but is network-based.

Data coupling for malware identification and analysis is its biggest strength. By using data coupling that is embedded into the signatures’ metadata, McAfee Network Threat Response can confirm that a vulnerability appeared and was attempted to be exploited. When it discovers both a vulnerability and a means to exploit it in the same stream, it confirms the attack.

Analyzing malware
McAfee Network Threat Response is a framework that associates validation of alarms, analyzing the payload of the activity. It looks for Malware that is using network exploits to move on the network, and then captures that malware for analysis and response.

It provides real-time capture and analysis of malware/threats inside your network. It finds new behaviors unique to your network, activity you have never seen before, accelerating your analysis and response. The result is a reduction in analyst’s time-to-evaluate and in time-to-confirmation while increasing the sensor-to-analyst ratio.

The McAfee Network Threat Response shows you confirmed attacks, reducing your time in sifting through thousands of alerts. All network traffic is labeled. Encoded data is decoded. Malware embedded in files is analyzed layer by layer.

Threat signatures
McAfee Network Threat Response provides insight into the network traffic using a large signature database as well as templates (associated code). The SNORT compatible malware signature database contains over 19,000 signatures, growing at a rate of about 200 new signatures per month. NTR helps create new signatures to block future attacks. You can even add your own SNORT compatible signatures.

Responding to malware
McAfee Network Threat Response can aid the compromised system in recovering from the detected attack. It can even replay the attack if desired.

Templates are associated with triggers (signatures), which:

  1. Decode payloads
  2. Recover malware (intercept / download)
  3. Passes malware on for evaluation

The benefits include:

  • Captures malware binary before system obfuscation, file names
  • DNS names and network addresses from attack
  • User names and passwords for backdoor scripts
  • Download vectors (http [adodb, xhtml], ftp, tftp, and tcpbind)

McAfee integration
McAfee Network Threat Response typically works in conjunction with an enforcement appliance like McAfee Network Security Platform (NSP / IntruShield) or McAfee Firewall Enterprise (Sidewinder). New malware is captured and sent to McAfee Artemis Technology to prevent further infection. NSP provides payload-based coverage to compliment NSP’s vulnerability-based and exploit-based coverage. NTR is stream-based and checks packet headers for abnormalities.

Web-based management console
The McAfee Network Threat Response Control Center (management console) appliance provides simple, centralized, web-based management of Network Threat Response sensor appliances. It can manage multiple NTR sensors. Control Center is also installed on each sensor appliance for single-box evaluation purposes, however using it will degrade the sensors performance if enabled.

Flexible configurations Diagram

Flexible configurations
McAfee Network Threat Response has several different modes:

1. IDS – The Sensor appliance passively listens to network traffic to discover threats. In this mode, the appliance is connected to one of the following:

  • Mirror (SPAN) network switch port (default)
  • Network TAP device

2. Decoy – The Sensor appliance is assigned one or more IP addresses, and masquerades as a vulnerable host to lure and capture attacks. In this mode, the appliance is connected to a conventional network switch port. Also referred to as a honey pot or endpoint.

3. Pcap – The Sensor appliance reads in captured packets from a packet capture file.

Accurate, enterprise-wide threat analysis

  • Confirmed attacks, malware listings, scripts, binaries, sessions
  • Industry leading shell code detector
  • GEO IP to determine who is searching your network
  • Receive continuous threat updates 24/7 from the global research team at McAfee Avert Labs

Network-class platform with multi-gigabit performance
McAfee Network Threat Response is the perfect fit for enterprises that need real-time security confidence with multi-gigabit performance. Each appliance is built on quality Dell hardware. You get carrier class reliability with the A1000, offering up to 10-Gbps performance with plenty of monitoring ports.

Specifications:

Sensor Hardware Components
Models A1000 A200 A100 A50 ACC A50VM
Role Sensor Appliance Sensor Appliance Sensor Appliance Sensor Appliance Management Console Appliance Sensor Virtual Machine
Performance throughput Up to 10 Gbps Up to 2 Gbps Up to 1 Gbps Up to 500 Mbps Multiple Sensors Up to 500 Mbps
Ports
1 Gigabit Ethernet ports 7 7 3 3 0
10 Gigabit Ethernet ports 2 0 0 0 0
Dedicated management ports (1 GbE) 1 1 1 1 4
Mode of Operation
SPAN port monitoring (passive) Yes Yes Yes Yes Yes
Network TAP mode (IDS) Yes Yes Yes Yes Yes
Decoy mode (honey pot) Yes Yes Yes Yes Yes
Packet Filter mode w/fail open No Yes No No No
Virtual Machine No No No No No Yes
Hardware
Dell PowerEdge TBD R610 R610 R200 R610 VMware ESX Image
CPU Cores 16 8 4 4 8
CPU 4x Intel Nehalem Quad-Core chips 2.66GHz+ 2x Intel Nehalem E5540 Xeon Quad-Core chips 2.53GHz 1x Intel Nehalem E5540 Xeon Quad-Core chip 2.53GHz 1x Intel X3360 Xeon Quad Core chip 2.83GHz 2x Intel Nehalem E5540 Xeon Quad-Core chips 2.53GHz
Memory 24GB 12GB 6GB 2GB 12GB
Hard Drives 4x 300GB Serial-Attached SCSI 4x 300GB Serial-Attached SCSI 2x 300GB Serial-Attached SCSI 1x 250GB SATA 4x 300GB Serial-Attached SCSI
Onboard NICs 4x 1GbE 4x 1GbE 4x 1GbE 2x 1GbE 4x 1GbE
Additional NICs Dual Port 10GbE NIC (fiber) Intel Quad Port 1GbE NIC (copper) Intel Quad Port 1GbE NIC (copper) w/fail open No Dual Port 1GbE NIC (copper) No
NetLogic Card NLS2008HAP No No No No No
Operating System RHEL 5 RHEL 5 RHEL 5 RHEL 5 RHEL 5 RHEL 5
High availability
Redundant power Yes Yes Yes No Yes
RAID Level RAID-10 RAID-10 RAID-1 No RAID-10
Physical
Form Factor 4U 1U 1U 1U 1U
Chassis Dimensions 6.8"(H) x 17.6" (W) x 27.6"(D) 1.68"(H) x 18.99" (W) x 30.39"(D) 1.68"(H) x 18.99" (W) x 30.39"(D) 1.68"(H) x 17.60" (W) x 21.50"(D) 1.68"(H) x 19.99" (W) x 30.39"(D)
Shipping Dimensions TBD 37.50"(W) x 11.50"(H) x 24.25"(D) each 37.50"(W) x 11.50"(H) x 24.25"(D) each 35.00"(W) x 10.25"(H) x 24.75"(D) each 37.50"(W) x 11.50"(H) x 24.25"(D) each
Weight 92 lbs. 39 lbs. 39 lbs. 26 lbs. 39 lbs.
Power consumption 1570w 717w 717w 345w 717w
Power input 90–264VAC (47-63Hz)
Temperature 10° to 35° C (operating), -40° to 65° C (storage)
Relative humidity (non-condensing) 20% to 80% (operating), 5% to 95% (storage)
Altitude -50 to 10,000 feet (operating), -50 to 35,000 feet (storage)
Safety certification NRTL (USA), CE (Europe), IRAM, BELLIS, SCC (Canada), CNCA or CCC, KONCAR, TUV, IECEE CB, SII, OTAN - CKT, KEBS, NYCE or NOM, INSM, SONCAP, NEMKO, GOST, KSA ICCP (R610 only), NRCS / SABS, BSMI, UKRTEST or UKRSERTCOMPUTER, STZ
EMI certification Class A for: FCC (USA), CE (Europe), ACMA or C-Tick, BELLIS, KVALITET, ICES (Canada), CNCA or CCC, KONCAR, SII, VCCI, OTAN - CKT, INSM, NEMKO, GOST, SABS, KCC / BCC, BSMI, UKRTEST or UKRSERTCOMPUTER, ICT

Documentation:

PDF File
Download the McAfee Network Threat Response Datasheet (PDF).

 

McAfee Products
McAfee Network Threat Response A50 Hardware
McAfee Network Threat Response A50 Appliance
Supports 4 1-Gigabit Ethernet interfaces and delivers up to 500Mbps traffic analysis performance. One AC power supply standard.
#NTR-A050-BA
List Price: $30,000.00
Our Price: $25,500.00
McAfee Network Threat Response A100 Hardware
McAfee Network Threat Response A100 Appliance
Supports 4 1-Gigabit Ethernet interfaces and delivers up to 1Gbps traffic analysis performance. Includes RAID-1 for higher performance.
#NTR-A100-BA
List Price: $70,000.00
Our Price: $59,500.00
McAfee Network Threat Response A200 Hardware
McAfee Network Threat Response A200 Appliance
Supports 8 1-Gigabit Ethernet interfaces and delivers up to 2Gbps traffic analysis performance. Includes RAID 1+0 for higher performance
#NTR-A200-BA
List Price: $85,000.00
Our Price: $72,250.00
McAfee Network Threat Response Control Center Hardware
McAfee Network Threat Response Control Center Appliance
Supports 8 1-Gigabit Ethernet interfaces and delivers up to 2Gbps traffic analysis performance. Includes RAID 1+0 for higher performance
#NTR-MGMT-BA
List Price: $30,000.00
Our Price: $25,500.00
McAfee Supports
McAfee Network Threat Response A50 Support
McAfee Network Threat Response A50 1 year Gold Software Support & Onsite Next Business Day Hardware Support
*Note: McAfee Hardware and Gold Software Support SKU is required to be sold with the appliance and provided to McAfee on one consolidated purchase order.
#NYVA50BNBDA
List Price: $6,000.00
McAfee Network Threat Response A50 1 year Onsite Same Day 24x7 Hardware Support Upgrade - from Next Business Day
*Note: McAfee Hardware and Gold Software Support SKU is required to be sold with the appliance and provided to McAfee on one consolidated purchase order.
#NYVA50BSDA
List Price: $3,000.00
McAfee Network Threat Response A100 Support
McAfee Network Threat Response A100 1 year Gold Software Support & Onsite Next Business Day Hardware Support
*Note: McAfee Hardware and Gold Software Support SKU is required to be sold with the appliance and provided to McAfee on one consolidated purchase order.
#NYVA100BNBDA
List Price: $14,000.00
McAfee Network Threat Response A100 1 year Onsite Same Day 24x7 Hardware Support Upgrade - from Next Business Day
*Note: McAfee Hardware and Gold Software Support SKU is required to be sold with the appliance and provided to McAfee on one consolidated purchase order.
#NYVA100BSDA
List Price: $7,000.00
McAfee Network Threat Response A200 Support
McAfee Network Threat Response A200 1 year Gold Software Support & Onsite Next Business Day Hardware Support
*Note: McAfee Hardware and Gold Software Support SKU is required to be sold with the appliance and provided to McAfee on one consolidated purchase order.
#NYVA200BNBDA
List Price: $17,000.00
McAfee Network Threat Response A200 1 year Onsite Same Day 24x7 Hardware Support Upgrade - from Next Business Day
*Note: McAfee Hardware and Gold Software Support SKU is required to be sold with the appliance and provided to McAfee on one consolidated purchase order.
#NYVA200BSDA
List Price: $8,500.00
McAfee Network Threat Response Control Center Support
McAfee Network Threat Response Control Center 1 year Gold Software Support & Onsite Next Business Day Hardware Support
*Note: McAfee Hardware and Gold Software Support SKU is required to be sold with the appliance and provided to McAfee on one consolidated purchase order.
#NYVCCBNBDA
List Price: $6,000.00
McAfee Network Threat Response Control Center 1 year Onsite Same Day 24x7 Hardware Support Upgrade - from Next Business Day
*Note: McAfee Hardware and Gold Software Support SKU is required to be sold with the appliance and provided to McAfee on one consolidated purchase order.
#NYVCCBSDA
List Price: $3,000.00
McAfee Software
McAfee Network Threat Response A50VM Virtual Machine (VMware) Software - Perpetual License
McAfee Network Threat Response A50VM Virtual Machine (VMware) Software, 1-+ Virtual Machines, 1-Year
*Perpetual License with 1-Year Gold Software Support
*Price per virtual machine. Quantity must be 1 or greater
#TVMCKE-AAA
List Price: $38,800.00
Our Price: $32,980.00
McAfee Network Threat Response A50VM Virtual Machine (VMware) Software
McAfee Network Threat Response A50VM Virtual Machine (VMware) Software, 1-+ Virtual Machines, 1-Year
*1-Year Gold Software Support
*Price per virtual machine. Quantity must be 1 or greater
#TVMYCM-AAA
List Price: $7,800.00
Our Price: $6,630.00
McAfee Network Threat Response Traffic Filter (500Mbps) Software - Perpetual License
McAfee Network Threat Response Traffic Filter Software, 1-+ Virtual Machines, 1-Year
*Perpetual License with 1-Year Gold Software Support
*Price per virtual machine. Quantity must be 1 or greater
#TFSCKE-AAA
List Price: $13,800.00
Our Price: $11,730.00
McAfee Network Threat Response Traffic Filter (500Mbps) Software
McAfee Network Threat Response Traffic Filter Software, 1-+ Virtual Machines, 1-Year
*1-Year Gold Software Support
*Price per virtual machine. Quantity must be 1 or greater
#TFSYCM-AAA
List Price: $2,800.00
Our Price: $2,380.00