"The marriage of [these] technologies creates a better way for the enterprise to safeguard itself from threats that could compromise the network"
— Mike Montecillo, analyst, Enterprise Management Associates
 

    Quick Contact

    First Name:

    Last Name:

    Company:

    Email:

    Phone:

    State:

    What can we do for you?

      


    Click here for more contact options.

  •  

 
 

NitroGuard - Network IPS and SEM

Intrusion prevention system



Network-based Intrusion Prevention (IPS)

NitroView Enterprise Security Management, content aware SIEM
How to Buy
Contact Us to request a demo, or
call us at 888-LOG-SIEM

Features at a Glance
High-speed Intrusion Detection & Prevention

Integrated Firewall

Dynamic Blacklists

Network flow collection

Central rule & policy management

Fully integrated with NitroView ESM to support advanced security and compliance use cases

Industry-leading threat detection:
  • Signature & Anomaly based detection
  • Extensive signature library with live updates
  • Throughputs up to 6Gbps with active rule-sets
  • Advanced threat prevention based on NitroView ESM's broad correlation and detection capabilities

More Information
NitroGuard Intrusion Prevention (IPS) Datasheet
NitroSecurity Solution Brochure
Awards
Testimonials
IPS Product Specs

NitroGuard is an intrusion prevention appliance that actively detects, analyzes, and protects the network from an array of security attacks, including viruses, worms, spyware, Denial-of-Service (DoS) attacks, and other forms of malware, as well as unknown or zero-day attacks. Utilizing the power of our patented relational data management engine, NitroGuard identifies and neutralizes threats and detects anomalies — in real time, before they disrupt the network and impact the business.

High Performance. Really High

Innovative Intrusion Prevention from the creators of SNORT® IPS

NitroSecurity created the first Snort-based IPS technology: Snort_Inline, which is widely used today. We've combined that experience with further innovations in IPS, as well in data collection, network flow, and security information analysis technology in order to provide a highly efficient, highly protective IPS. Interested in Snort_Inline? Visit them at Snort_Inline's SourceForge page.

Learn more about our innovations in IPStechnology.

Stop Complex Attacks

NitroGuard IPS can stop detect complex threats and provide the actionable intelligence required to fully investigate security incidents. Using NitroView's Event Correlation capabilities, along with the industry's fastest data management engine, security events, logs and network behavior are analyzed in real-time to detect complex threats. As incidents occur, NitroView is able to notify security analysts in real-time, and provide immediate access to the information required to mitigate and remediate the threat.


Real-time data management engine

NitroView SIEM NitroEDB is a high-performance relational data management engine that enables many of the advanced features found in NitroGuard and NitroView. The importance of this performance gain can not be overstated: it allows for NitroGuard to operate at high throughput, with a high number of concurrent sessions, while at the same time analyzing flow data for anomalies. It also provides data management performance high enough to support a real-time user interface, where queries and analytics are returned in seconds, even on massive amounts of historical data — and without effecting NitroGuard's ability to continue processing new events.

"Last year during our registration process alone we had between 10 and 20 virus outbreaks. This year, as a result of our NitroSecurity implementation, we have not had a single one and we virtually eliminated illegal file-sharing."

William Souder
Director of Network Operations & Information Security Officer
Berry College

Purpose-Built Performance

NitroView SIEMNitroGuard appliances are purpose-built, using high-performance memory, network I/O, and RAID controllers — all tuned to provide the best possible performance and reliability.

Ideal for high-performance networks, NitroGuard supports bandwidths of 250Mbps on the NS-IPS-1200, up to 1.5 Gbps on the NS-IPS-4200. Each IPS uses extensive "out of the box" anomaly rules, yet also allows enterprises to easily change or customize the response to various threats: use analytical capabilities to adjust anomaly rules to real network trends; easily edit rules or add new ones using standard SNORT® syntax; or add NitroView ESM to provide post-event data correlation and processing, including contextual forensics and compliance reporting.

An IPS with a Brain

NitroView SEMNitroView SEM

NitroGuard has brawn, and brains too: each NitroGuard IPS comes with an installable version of NitroView ESM — for device management, event/flow correlation, and analytics "not typically seen in an IPS". Of course, for large networks, NitroView ESM is available as an appliance as well, offering the same performance advantages and reliability as NitroGuard IPS.

Multiple Personalities

snort_inlineNitroGuard is more than a powerful IPS — it's several powerful IPS's in one box. Using Virtual IPS technology, each NitroGuard can simultaneously operate individual IPS rule-sets across multiple physical gigabit Ethernet ports, or even by VLAN. Virtual IPS increases flexibility by applying specific rules to specific areas of the network, and also improves performance through multi-tasking.



Still the Same NitroGuard that you Love

Our new NitroGuard IPS family supports all of the original features that made NitroGuard a success:

  • In-band secure management via an encrypted channel.
  • Easy-to-use, intuitive interface using either NitroView ESS for device and SEM functionality, or NitroView ESM for full SIM capabilities.
  • A large and continually evolving signature library, complete with advanced behavioral anomaly detection techniques to protect enterprises from new or emerging security risks.
  • Reliability with integrated bypass capabilities, redundant power, and a self-healing data engine.

Specifications 

NitroGuard IPS Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model                     Description      Throughput      Copper
Ports     
Fiber
Ports     
NS-IPS-5450-R NitroGuard IPS 5000, 3U IPS appliance supporting approximately 4 to 5Gbps & 1.2m connections. Includes redundant power and a bypass NIC. 4-6 Gbps 12x1Gbps 4x10Gbps
NS-IPS-4245-R NitroGuard IPS4000, 1U IPS appliance supporting approximately 2Gbps & 1.5m connections. Includes redundant power and a bypass NIC. 2 Gbps 2, 4, 8 2, 4
NS-IPS-2250-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 750Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 750 Mbps 2, 4, 8 2, 4
NS-IPS-2230-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 500Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 500 Mbps 2, 4, 8 2, 4
NS-IPS-1225 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 250Mbps & 1.2m connections. Includes single power and a bypass NIC. 250 Mbps 2, 4 2, 4
NS-IPS-1160 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 150Mbps & 1.2m connections. Includes single power and bypass NIC. 150 Mbps 2 N/A
NS-IPS-110 NitroGuard IPS 100, Set-Top IPS appliance supporting approximately 50Mbps & 1.2m connections. Includes single power and a 2 port 10/100/1000 Base-TX copper NIC (no bypass). 50 Mbps 2 N/A

Related Products

NitroView Enterprise Security Manager Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model           Description                         Events/sec     Report   
speed*    
HDD**    
NS-ELM-XXXX NitroView Enterprise Log Manager (ELM) Integrated Log Management for NitroView ESM & NitroView Receiver
 NS-ESM-X5 NitroView ESM X5 "High Speed" Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for large enterprise networks. 7TB local storage plus 500GB of in-memory storage for etremely high performance. One 3U appliance, plus one 2U Appliance. 40 Million 1 Billion events/sec 7TB +
500GB RAM
 NS-ESM-5750-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for medium to large enterprise networks. 7TB local storage. 3U Appliance. 4 Million 100 Million events/sec 7 TB
 NS-ESM-5510-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions. 3.75TB local storage, 3U appliance 3 Million 50 Million events/sec 3.75 TB
 NS-ESM-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. 2.5TB local storage. 3U appliance. 2 Million 25 Million events/sec 2.5 TB
 NS-ESMRCV-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. Rated for 5,000 events per second and manages up to (5) NitroSecurity devices (IPS, DAM, or APM). 5,000 25 Million events/sec 2.5 TB
 NS-ESMRCV-4245-R NitroView ESM 4000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 1.5 TB local storage. 1U appliance. Rated for 1,000 events per second and manages up to (3) NitroSecurity devices (IPS, DAM, or APM). 1,000 25 Million events/sec 1.5 TB
 NS-NRC-4245 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 18,000 events per second. 18,000 - 1 TB
 NS-NRC-2250 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 15,000 events per second. 15,000 - 1 TB
 NS-NRC-2230 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000 - 1 TB
 NS-NRC-1225 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000 - 500GB
 NS-ESS-5205 NitroView ESM 5000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. Redundant power, 2.5TB local storage. 3U appliance. 150,000 (NitroSecurity devices only) 25 Million events/sec 2.5 TB
 NS-ESS-2230-R NitroView ESM 2000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. 500GB local storage. 1U appliance. 150,000 (NitroSecurity devices only) 15 Million 500GB

* Typical SIEM reports (queries) will complete in a few seconds, even on very large event stores.

** NitroView ESM 5000 models utilize a raid 10 drive configuration, as well as redundant, dedicated drives for OS storage. The number listed above represents the usable capacity for event, log and flow storage.

*** The maximum number of supported devices per ESM is determined by the receiver model(s) used for collection.

Click to see a current list of supported data sources


NitroView Database Monitor Specifications

Select a Model for Specifications

Model                  Description      Appliance      Supported DBs      Events/Sec     
NS-DBM-4245-R NitroView DBM 4000, Database Monitor Pack. 1U Appliance good DB2, Oracle, MS SQL, MySQL, SyBase 15,000
NS-DBM-2250-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 10,000
NS-DBM-2230-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 5,000

NitroView Enterprise Log Manager Specifications

Select a Model for Specifications

model              Description      Logs / Sec     
NS-ESMLM-4245-R NitroView ESM / ELM 4000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 1 TB local storage. 1U appliance. 1,000
NS-ESMLM-5205-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. 2,500
NS-ESMLM-5510-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 3.75 TB local storage. 3U appliance. 5,000
NS-ELM-5510-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 3.75 TB local storage. 3U appliance. 35,000
NS-ELM-5205-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 2.5 TB local storage. 3U appliance. 20,000
NS-ELM-4245-R NitroView ELM 4000 Enterprise Log Manager provides Compliant Log Management functions. Supports network / SAN storage options. No local storage. 1U appliance. 40,000
NS-ELM-5750-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 7 TB local storage. 3U appliance. 50,000
NS-NRCLM-4245-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000
NS-NRCLM-2250-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 8,000 events per second. 8,000
NS-NRCLM-2230-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000
NS-LC-2250-R NitroView LogCaster 2000, 1U appliance. Includes (500) LogCaster Agent Licenses. Rated for 10,000 events per second. 10,000
NS-LC-2230-R NitroView LogCaster 2000, 1U appliance. Includes (250) LogCaster Agent Licenses. Rated for 5,000 events per second. 5,000
NS-LC-AGT-200 NitroView LogCaster Large Syslog Device Agent License for quantity 200 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-100 NitroView LogCaster Large Syslog Device Agent License for quantity 100 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-50 NitroView LogCaster Large Syslog Device Agent License for quantity 50 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-25 NitroView LogCaster Large Syslog Device Agent License for quantity 25 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -

NitroSecurity, NitroGuard and NitroView are trademarks of NitroSecurity, Inc. 'Snort' is a registered trademark of Sourcefire, Inc.





 

Search NitroSecurity.com