|
"The Leading Intrusion Detection System"
Dragon is the award winning UNIX based Intrusion Detection System. It provides an extremely comprehensive intrusion detection software service equipped with an adundence of important functionality.
The Dragon system comprises:
Network Based IDS
The Dragon Sensor is a network monitor. It watches live network packets and looks for signs of computer crime, network attacks, network misuse and anomalies. When it observes an event, the Dragon Sensor can send pager alerts/messages, email messages, and take action to stop the event and record it for future forensic analysis. Typically, Dragon Sensors are deployed on standalone systems in front of firewalls or at key network choke points.
Dedicated Analysis and Alerting Server
The Dragon Server facilitates secure management of all Dragon Sensors and Dragon Squires. It also aggregates all alerts into one central database so that disparate attack information can be correlated. The Dragon Server includes a variety of reporting and analysis tools as well as the ability to customize alerts via email, SNMP or syslog messages.
Secure Web and Console Access
All Dragon products can be administered and analyzed securely through command line and web GUI interfaces. This drastically lowers overall deployment and operation costs from running an enterprise IDS (Intrustion Detection System).
Performance
The Dragon Sensor is simply the fastest NIDS available today. It has been tested in real world conditions against many of the other NIDS products on the market today. We encourage you to test it out on your high-speed networks.
Network Integrity
Believe it or not, many network intrusion detection software products do not reassemble network streams that occur across multiple packets, out of order packets or that contain fragmented packets. This allows network attacks to scramble their network probes and attacks and avoid detection. Dragon Sensor is not effected by these techniques. Dragon Squire complements and fills in any gaps, which arise from future anti-IDS avoidance techniques.
Scaleable Sensor/Squire Management
The Dragon Server can easily manage thirty Dragon Sensors on heavily loaded 100Mb networks. This minimizes infrastructure costs when deploying IDS consoles. Dragon Server has been tested in laboratory conditions for use in monitoring 100+ Dragon Sensors. This scalability will also allow the Dragon Server to manage fifty Dragon Squire engines in addition to the Dragon Sensors.
Open Signatures
Dragon Sensor and Dragon Squire signatures are contained in ASCII text libraries. They are fully documented with copious references to CVE and Bugtraq information. More importantly, they can be trivially modified to detect new versions of current attacks. It takes ten minutes for most Dragon Sensor users to learn how to write new signatures. Dragon Squire will have a similar signature language such that end users will not have to learn a completely new language.
Intrusion Detection - An Issue That Cannot Be Ignored
Dragon is the award winning UNIX based Intrusion Detection Software System from Network Security Wizards (NSW) in the USA. Portcullis, the exclusive Europeon distributors, also provide support, updates, installation and configuration and of course the full managed Security Service throughout the continent.
If you are serious about security, intrusion detection is an issue which you cannot ignore. Why not contact us for more information or download an evaluation copy?
Further Information
Return to main page
|