-

LiveAction Launches ThreatEye NV, a Network Detection and Response Platform That Delivers Complete Encrypted Traffic Analysis and Visibility

Combining next-generation data collection, advanced behavior analysis and streaming machine learning, ThreatEye NV uses more than 150 flow features with Deep Packet Dynamics for unprecedented threat and anomaly detection

PALO ALTO, Calif.--(BUSINESS WIRE)--LiveAction, a leader in end-to-end visibility for network security and performance, today announced the release of ThreatEye NV. A network detection and response platform (NDR), ThreatEye NV combines next-generation data collection, advanced behavior analysis and streaming machine learning to give SecOps teams unprecedented visibility into encrypted traffic, threats and network anomalies. Utilizing Deep Packet Dynamics (DPD) that eliminates the need for payload inspection, the platform analyzes more than 150 packet traits and behaviors across multi-vendor, multi-domain and multi-cloud network environments. This helps accelerate real-time threat detection, eliminates encryption blindness, validates encryption compliance, and allows teams to better secure the entire network and coordinate responses with other security tools such as SIEM and SOAR.

“Having comprehensive visibility into encrypted traffic and being able to automate advanced analysis of that data in real-time is critical to protecting against today’s advanced threats. Traditional tools rely on deep packet inspection or rules-based monitoring, which impacts performance and is proven to no longer be sufficient,” said Thomas Pore, Director of Security Products at LiveAction. “ThreatEye NV uses new DPD technology that provides high-fidelity flow records that analyze more than 150 packet and flow features, all without payload inspection, which can negatively impact performance. When combined with advanced data collection and machine learning models, customers get the industry’s most powerful NDR solution.”

ThreatEye NV was designed to help organizations and their SecOps teams improve threat detection and prevent adversaries from executing successful disruptive and damaging attacks. Key updates to the platform include more than 150 new detection capabilities including advanced behavior anomaly detection, encrypted metadata threat detections, plaintext metadata threat detections, AI/ML-driven detections, AI/ML-driven encryption inventory, DNS/DoH detections, and Active Exploit Detections. The platform also offers continuous packet capture with single-click pivot-to-PCAP through a new ThreatEye NV probe integration with LiveAction's LiveWire, which extends packet-to-flow visibility of virtual infrastructure. The combination of threat detection and encrypted traffic analysis with packet capture delivers unmatched visibility for SecOps teams looking to improve their security strategy and response capabilities.

Key benefits and features of ThreatEye NV:

  • Real-Time Threat and Anomaly Detection – ThreatEye NV’s Deep Packet Dynamics (DPD) is agnostic to packet contents and uses a rich metadata set of more than 150 packet dynamic features to create a historical inventory of traits and behaviors for profiling and fingerprinting, a technique that works equally well with both encrypted and unencrypted traffic. Machine Learning models are applied to identify advanced behavioral threat actor anomalies and the platform is designed to process millions of events per second in real-time.
  • Eliminate Encryption Blindness and Validate Compliance– Increased adoption of encrypted network protocols is causing the erosion of network visibility for security teams. As a result, legacy tools are losing visibility. Encrypted traffic analysis and the application of ML to DPD enables encrypted traffic analysis without decryption or performance degradation. The platform also provides encryption-policy-specific alerting and reporting for security compliance.
  • Simple Deployment to Secure the Entire Network – ThreatEye NV is a SaaS offering with software sensors deployed as containerized software applications. This containerized approach allows the solution to be deployed either on-premises, in a private or public cloud, or a mixture of both. From core to edge to cloud, ThreatEye NV includes lightweight, easy-to-deploy software sensors available for deployment anywhere and everywhere visibility is needed.
  • SOC Enabled– With a multi-stage analysis pipeline that correlates and enriches traffic with finding details, risk scores, and MITRE ATT&CK labeling, time to investigate and respond is dramatically decreased. Teams can respond in real-time and accelerate triage with integrated packet analysis. ThreatEye NV’s SaaS offering includes SOC-enabled dashboards to further drive response efficiency.
  • Coordinate a Cohesive Security Response – ThreatEye NV interconnects seamlessly with existing security tools like SIEMs, SOAR, and Threat Intelligence. Workflow automation with products like Cisco SecureX allows teams to take immediate action on security events to quarantine hosts or block threats. SIEM integration can provide a correlation with EDR events and malicious activity on previously unseen encrypted channels.
  • Streaming Machine Learning Analysis – Powered by a streaming machine learning engine, the platform ingests high-fidelity metadata generated by its software probes. The ML engine is purpose-built for network security and unlike traditional batch processing, streaming ML is fueled by analyzers – or models – engineered to analyze network traffic without multiple passes over the data stream. These models are custom-built for specific security and visibility use cases and scale via parallel processing.

For more information about ThreatEye NV, or to get a demo today, click here.

About LiveAction

LiveAction provides end-to-end visibility for network security and performance. By relying on a single source of truth – the packets – LiveAction gives modern enterprises the confidence needed to ensure the network is securely meeting business objectives, providing full network visibility to better inform NetOps and SecOps, and reducing the overall cost of network and security operations. By unifying and simplifying the source of collection, inspection, presentation, and analysis of network traffic, LiveAction empowers network and security professionals to proactively and quickly identify, troubleshoot, and resolve issues across increasingly large and complex networks. To learn more about LiveAction, visit https://www.liveaction.com.

Contacts

Justin Hall
Voxus PR
253-444-5442
jhall@voxuspr.com

LiveAction

Details
Headquarters: Palo Alto, CA
CEO: Stephen Stuut
Employees: 200+
Organization: PRI

Release Versions

Contacts

Justin Hall
Voxus PR
253-444-5442
jhall@voxuspr.com

More News From LiveAction

LiveAction Wins 2023 Global InfoSec Award for Most Innovative Network Detection and Response Solution at RSA Conference

SAN FRANCISCO--(BUSINESS WIRE)--RSA CONFERENCE – LiveAction, a leader in end-to-end visibility for network security and performance, today announced that ThreatEye has won the 2023 Cyber Defense Magazine Global InfoSec Award for Most Innovative Network Detection and Response (NDR) solution. At the RSA Conference, the ThreatEye platform was recognized for its ability to help secure networks from core to edge to cloud, and to detect threat actors with its AI-driven behavioral analytics and automa...

LiveAction's SVP of Channels and Alliances Honored as a 2023 CRN Channel Chief

PALO ALTO, Calif.--(BUSINESS WIRE)--LiveAction, a leader in end-to-end visibility for network security and performance, today announced that its SVP of Channels and Alliances, Chris Braden, was named to the CRN© 2023 Channel Chiefs list. This annual list identifies top IT channel vendor executives who continually demonstrate expertise, influence, and innovation in channel leadership. A panel of CRN editors selected the honorees for their channel dedication, industry stature and accomplishments...

LiveAction’s ThreatEye® Brings Together AI-driven Anomaly Detection and Predictive Threat Intelligence in New Dedicated UI Built for SOC Analysts

PALO ALTO, Calif.--(BUSINESS WIRE)--LiveAction, a leader in end-to-end network security and performance visibility, today announced the next generation of ThreatEye®, the company’s Network Detection and Response (NDR) platform. The latest release continues to build on the company’s advanced AI-driven Anomaly Detection capabilities with packet-based behavioral fingerprinting to identify behavior in encrypted traffic streams, and host-based behavioral detections. It includes a new User Interface...
Back to Newsroom