Download PDF
NETSCOUT > Case Studies > Omnis Cyber Intelligence Brings Value of Packet Data for Faster Incident Response
NETSCOUT Logo

Omnis Cyber Intelligence Brings Value of Packet Data for Faster Incident Response

Technology Category
  • Cybersecurity & Privacy - Intrusion Detection
  • Cybersecurity & Privacy - Malware Protection
  • Cybersecurity & Privacy - Network Security
Applicable Industries
  • Healthcare & Hospitals
Applicable Functions
  • Maintenance
  • Quality Assurance
Use Cases
  • Cybersecurity
  • Intrusion Detection Systems
Services
  • Cybersecurity Services
  • System Integration
The Challenge
The Network Operations team (NetOps) at the healthcare company wanted to expand their existing ISNG deployment but didn’t have the budget, so they approached the Security Operations team (SecOps) to show them the enhanced value of their packet-based solution vs. the NetFlow-based solution the security team was currently using. The SecOps team’s existing NetFlow-based platform was approaching end of life and required a significant investment to upgrade. With this issue, the SecOps team was interested but hesitant in a new platform, because they didn’t fully understand the capability of packet-derived data and preferred their existing NetFlow-based platform. The team used this platform on a daily basis, and that familiarity provided a lot of comfort to them. They believed this NetFlow-based solution was providing adequate information for them to be successful at identifying, investigating, and remediating threats. However, the team was open-minded throughout these conversations, coming to see the gaps in detail using NetFlow, such as identifying individual IP addresses using a particular protocol. They began to understand and value the different types of information that packet-based data would be able to provide.
About The Customer
For over 60 years, this company has provided the best in healthcare and the latest in medical technology, leveraging a network of more than 100 clinics and multiple major hospitals. This company was happy with their previous year’s purchase of NETSCOUT ISNG and nGeniusONE Service Assurance solution to ensure the performance and availability of their critical patient care and medical records applications. Seeing the value of a packet-based monitoring approach, the team wanted to expand on this investment and explore what more they could get out of the data, specifically for forensics purposes to help the Security Incident Response Team identify and remediate threats quickly and effectively. Both network operations and security operations teams reported to the assistant CTO, which helped bridge communication, foster collaboration, and show value to both organizations.
The Solution
After evaluating the value of packet-based monitoring, NETSCOUT’s Omnis Cyber Intelligence technology, and the added benefit of tool consolidation, the executive team determined packet-based monitoring was the best approach going forward, with NETSCOUT providing the best solution for both service assurance and security purposes. Using a single source of packets and metadata that provided value to the NetOps team, via NETSCOUT nGeniusONE, and value to the SecOps team via Omnis Cyber Intelligence helped bridge the gap between security and network operations. More specifically, with Omnis Cyber Intelligence, the security team can leverage their existing NETSCOUT ISNG investments for Smart Data, which is derived from NETSCOUT’s patented Adaptive Service Intelligence® (ASI) technology, which transforms wire traffic into smart data, providing real-time visibility into user experience for the most advanced and adaptable information platform to ensure security, manage risk, and drive service performance. Along with NETSCOUT ATLAS Intelligence Feed®, a highly curated, threat intelligence feed for detection of DDoS and other cyber threats. This combination helps turn massive amounts of wire data into actionable insights for efficient cyber threat detection and investigation.
Operational Impact
  • By moving to a packet-based monitoring approach and leveraging it for both network and security purposes, the security team was able to efficiently investigate threats to better understand them and determine risk and/or actions to take based on that risk.
  • Both NetOps and SecOps teams can collaborate to identify and manage issues more effectively to determine if the issue is related to network or security concerns. This allows both teams to view the same data, but from different perspectives, to gain better insights and remediate issues faster.
  • This also resulted in significant capital expense savings by consolidating their tools and avoiding a very costly upgrade with their previous solution.
Quantitative Benefit
  • Significant capital expense savings by consolidating their tools and avoiding a very costly upgrade with their previous solution.

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.