DiSARM
Abstract
DiSARM is a data management solution for large, heterogeneous network security datasets, including log files and intrusion detection system alerts. DiSARM provides scalable, real-time data capture of multi-terabyte network security data sets. Records are stored in their native format and are accessed by security analysts and developers via a set of APIs. The APIs provide single query access to data stored by DiSARM.
Applications
- Computer security analysis
- Network forensics analysis
- Network troubleshooting
Advantages
- Processes data at high speeds
- Can be configured for integration with existing network traffic collection
- Reports in standard formats
IP Status: Copyrighted work
Commercialization Strategy: Available both exclusively and non-exclusively
Reference Number: C-05,049
Posted: 03-07-2006
Contact:
Technology Transfer Division
Los Alamos National Laboratory
P.O. Box 1663, MailStop C333
(505) 665-9090
software@lanl.gov
LAUR-06-1652
|