Session Auditor

Session Auditor is a network-based human behavior auditing system. Unlike traditional log management systems which record discrete events happening in disparate computer systems and components, Session Auditor records and stores the entire session of human-system-application interaction. Recorded sessions can subsequently be retrieved and played back as required. Activities recorded include screen updates, mouse clicks and keyboard input. The entire session is visually recorded similar to observing the user “over the shoulder”. Session Auditor enhances and simplify audit systems by adopting a transparent network based approach. No complex and costly software (e.g. database, application server, server side agents, etc) is required.

Generally speaking, “audit system” for information systems are separated into two distinct kinds, namely “management” layer auditing and “technical” layer auditing. The former is mapped to auditing tools based on best practices and standards, such as ISO27001 (BS7799) and COBIT. But for the latter, there are numerous tools and approaches available for IT managers to choose from. These tools are typically implemented using log collection and analysis tools in the IDC’s security product category of SIEM (Security Information and Event Management). These logs are designed to record only the event results, without the details of the activities and operations. In other words, if security managers and auditors want to do in depth investigation and forensics, these logs have its limitation.

Session Auditor is an outstanding in-depth investigation and forensic tool. With its huge built-in storage (up to 5T Bytes), Session Auditor can record up to 5 months of network traffic in a high speed Ethernet (100Mb/s) environment. Session Auditor is a trustworthy “Black Box” in your operating environment, similar to the one found inside all aircrafts.


products

SAS1000 - Powerful Sensor and Datacenter for network behavior analysis and audit. SAL-200 - Lite version of Session Auditor, cost effective, perfect for SME and branch office!
sas1000 sal-200
Model Network Interface Storage Throughput Memo
SAL-200 4GBE 320GB 200Mb Branch office
SAL-400E 4GBE+4SFP 500GB 400Mb Small to Medium Data Center
SAL-1000 6GBE+4SFP Up to 1TB 1000Mb/2000Mb Medium Data Center
SAL-10000 8xGBE/6GBE+2SFP Up to 2TB 4000Mb/6000Mb Various Data Center
SAS-200 4GBE - 200Mb Enterprise, low to medium network traffic
SAS-400E 4GBE+4SFP - 400Mb Enterprise, medium network traffic
SAS-1000 6GBE+4SFP - 1000Mb/2000Mb Enterprise, high network traffic
SAS-10000 8GBE/6GBE+2SFP - 4000Mb/6000Mb Enterprise, high network traffic
SAD-400 2GBE 320GBx6 400Mb Enterprise, medium network traffic
SAD-2000 2GBE 500GBx12 2000Mb Enterprise, distributed deployment