Download PDF
Omnis Cyber Intelligence Brings Value of Packet Data for Faster Incident Response
Technology Category
- Cybersecurity & Privacy - Intrusion Detection
- Cybersecurity & Privacy - Malware Protection
- Cybersecurity & Privacy - Network Security
Applicable Industries
- Healthcare & Hospitals
Applicable Functions
- Maintenance
- Quality Assurance
Use Cases
- Cybersecurity
- Intrusion Detection Systems
Services
- Cybersecurity Services
- System Integration
The Challenge
The Network Operations team (NetOps) at the healthcare company wanted to expand their existing ISNG deployment but didn’t have the budget, so they approached the Security Operations team (SecOps) to show them the enhanced value of their packet-based solution vs. the NetFlow-based solution the security team was currently using. The SecOps team’s existing NetFlow-based platform was approaching end of life and required a significant investment to upgrade. With this issue, the SecOps team was interested but hesitant in a new platform, because they didn’t fully understand the capability of packet-derived data and preferred their existing NetFlow-based platform. The team used this platform on a daily basis, and that familiarity provided a lot of comfort to them. They believed this NetFlow-based solution was providing adequate information for them to be successful at identifying, investigating, and remediating threats. However, the team was open-minded throughout these conversations, coming to see the gaps in detail using NetFlow, such as identifying individual IP addresses using a particular protocol. They began to understand and value the different types of information that packet-based data would be able to provide.
About The Customer
For over 60 years, this company has provided the best in healthcare and the latest in medical technology, leveraging a network of more than 100 clinics and multiple major hospitals. This company was happy with their previous year’s purchase of NETSCOUT ISNG and nGeniusONE Service Assurance solution to ensure the performance and availability of their critical patient care and medical records applications. Seeing the value of a packet-based monitoring approach, the team wanted to expand on this investment and explore what more they could get out of the data, specifically for forensics purposes to help the Security Incident Response Team identify and remediate threats quickly and effectively. Both network operations and security operations teams reported to the assistant CTO, which helped bridge communication, foster collaboration, and show value to both organizations.
The Solution
After evaluating the value of packet-based monitoring, NETSCOUT’s Omnis Cyber Intelligence technology, and the added benefit of tool consolidation, the executive team determined packet-based monitoring was the best approach going forward, with NETSCOUT providing the best solution for both service assurance and security purposes. Using a single source of packets and metadata that provided value to the NetOps team, via NETSCOUT nGeniusONE, and value to the SecOps team via Omnis Cyber Intelligence helped bridge the gap between security and network operations. More specifically, with Omnis Cyber Intelligence, the security team can leverage their existing NETSCOUT ISNG investments for Smart Data, which is derived from NETSCOUT’s patented Adaptive Service Intelligence® (ASI) technology, which transforms wire traffic into smart data, providing real-time visibility into user experience for the most advanced and adaptable information platform to ensure security, manage risk, and drive service performance. Along with NETSCOUT ATLAS Intelligence Feed®, a highly curated, threat intelligence feed for detection of DDoS and other cyber threats. This combination helps turn massive amounts of wire data into actionable insights for efficient cyber threat detection and investigation.
Operational Impact
Quantitative Benefit
Related Case Studies.
Case Study
Hospital Inventory Management
The hospital supply chain team is responsible for ensuring that the right medical supplies are readily available to clinicians when and where needed, and to do so in the most efficient manner possible. However, many of the systems and processes in use at the cancer center for supply chain management were not best suited to support these goals. Barcoding technology, a commonly used method for inventory management of medical supplies, is labor intensive, time consuming, does not provide real-time visibility into inventory levels and can be prone to error. Consequently, the lack of accurate and real-time visibility into inventory levels across multiple supply rooms in multiple hospital facilities creates additional inefficiency in the system causing over-ordering, hoarding, and wasted supplies. Other sources of waste and cost were also identified as candidates for improvement. Existing systems and processes did not provide adequate security for high-cost inventory within the hospital, which was another driver of cost. A lack of visibility into expiration dates for supplies resulted in supplies being wasted due to past expiry dates. Storage of supplies was also a key consideration given the location of the cancer center’s facilities in a dense urban setting, where space is always at a premium. In order to address the challenges outlined above, the hospital sought a solution that would provide real-time inventory information with high levels of accuracy, reduce the level of manual effort required and enable data driven decision making to ensure that the right supplies were readily available to clinicians in the right location at the right time.
Case Study
Gas Pipeline Monitoring System for Hospitals
This system integrator focuses on providing centralized gas pipeline monitoring systems for hospitals. The service they provide makes it possible for hospitals to reduce both maintenance and labor costs. Since hospitals may not have an existing network suitable for this type of system, GPRS communication provides an easy and ready-to-use solution for remote, distributed monitoring systems System Requirements - GPRS communication - Seamless connection with SCADA software - Simple, front-end control capability - Expandable I/O channels - Combine AI, DI, and DO channels
Case Study
Driving Digital Transformations for Vitro Diagnostic Medical Devices
Diagnostic devices play a vital role in helping to improve healthcare delivery. In fact, an estimated 60 percent of the world’s medical decisions are made with support from in vitrodiagnostics (IVD) solutions, such as those provided by Roche Diagnostics, an industry leader. As the demand for medical diagnostic services grows rapidly in hospitals and clinics across China, so does the market for IVD solutions. In addition, the typically high cost of these diagnostic devices means that comprehensive post-sales services are needed. Wanteed to improve three portions of thr IVD:1. Remotely monitor and manage IVD devices as fixed assets.2. Optimizing device availability with predictive maintenance.3. Recommending the best IVD solution for a customer’s needs.
Case Study
HaemoCloud Global Blood Management System
1) Deliver a connected digital product system to protect and increase the differentiated value of Haemonetics blood and plasma solutions. 2) Improve patient outcomes by increasing the efficiency of blood supply flows. 3) Navigate and satisfy a complex web of global regulatory compliance requirements. 4) Reduce costly and labor-intensive maintenance procedures.
Case Study
Harnessing real-time data to give a holistic picture of patient health
Every day, vast quantities of data are collected about patients as they pass through health service organizations—from operational data such as treatment history and medications to physiological data captured by medical devices. The insights hidden within this treasure trove of data can be used to support more personalized treatments, more accurate diagnosis and more advanced preparative care. But since the information is generated faster than most organizations can consume it, unlocking the power of this big data can be a struggle. This type of predictive approach not only improves patient care—it also helps to reduce costs, because in the healthcare industry, prevention is almost always more cost-effective than treatment. However, collecting, analyzing and presenting these data-streams in a way that clinicians can easily understand can pose a significant technical challenge.