IT Central Station is now PeerSpot: Here's why

Top 8 Network Traffic Analysis (NTA) Tools

DarktraceAuvikVectra AICisco StealthwatchArista NDRSolarWinds NetFlow Traffic AnalyzerExtraHop Reveal(x)Corelight
  1. leader badge
    We are able to detect a lot of things, actually, and see what is happening in our network.The active threat dashboard is the most valuable feature of this solution.
  2. leader badge
    One of the most valuable features is the network overview charts and seeing how things are connected in real time. The overall intuitiveness of the network visualization is good. Its design works for us.
  3. Buyer's Guide
    Network Traffic Analysis (NTA)
    June 2022
    Find out what your peers are saying about Darktrace, Auvik, Vectra AI and others in Network Traffic Analysis (NTA). Updated: June 2022.
    611,060 professionals have used our research since 2012.
  4. leader badge
    It keeps up with the network traffic, which is a good thing. It provides more context to plain alerts compared to using an older system. So, it helps an analyst reduce the information overload.
  5. leader badge
    If you are using Darktrace or NAC solutions you can integrate Stealthwatch.StealthWatch lets me see the ports running in and out and the country. It has excellent reporting, telemetry, and artificial intelligence features. With the telemetry, I can set thresholds to detect sudden changes and the alarms go through the PLC parts. I can see all the ports running on that trunk.
  6. When I create a workbench query in Awake to do threat hunting, it's much easier to query. You get a dictionary popup immediately when you try to type a new query. It says, "You want to search for a device?" Then you type in "D-E," and it gives you a list of commands, like device, data set behavior, etc. That gives you the ability to build your own query.
  7. What the network team found most valuable in SolarWinds NetFlow Traffic Analyzer is that it helps them to troubleshoot or analyze the issue. For example, traffic that comes from our location: India, goes to the US, so for the network team to analyze where the traffic comes from and where it is directed, and whether the packets are being dropped, they use SolarWinds NetFlow Traffic Analyzer. The network team also likes that through the solution, they can analyze the complete traffic utilization and how they're going to use it. SolarWinds NetFlow Traffic Analyzer is user-friendly. The team finds it comfortable to use.
  8. report
    Use our free recommendation engine to learn which Network Traffic Analysis (NTA) solutions are best for your needs.
    611,060 professionals have used our research since 2012.
  9. We had useful information within the hour of deployment. The ability to trace back for historical analysis, as well as the behavioral analysis done with the security information, puts the user in a position to make an informed decision to mitigate the performance or security incidents. Regarding the security incidents, Reveal (x) is able to create incident cards that guide your teams through the incidents and gives you the option to delve into the transaction detail to potentially view payloads as well.
  10. Corelight is easy to use.The most valuable feature is the embedded IDS from Suricata.

Advice From The Community

Read answers to top Network Traffic Analysis (NTA) questions. 611,060 professionals have gotten help from our community of experts.
Rony_Sklar - PeerSpot reviewer
Rony_Sklar
PeerSpot (formerly IT Central Station)

AI has been introduced into many cybersecurity tools. How has this improved the efficacy of these tools? Are there any drawbacks?

reviewer1259193 - PeerSpot reviewer
reviewer1259193Efficiency has definitely improved, tool sets that I’m familiar with are… more »
2 Answers
VinodYadav - PeerSpot reviewer
VinodYadav
Senior Manager at Cyfuture India Pvt Ltd

Hello peers, 

I'm a Senior Manager at a large Tech Services company. I want to perform analysis of my network. 

Do you have any suggestions of NTA tools to look at?

Lucas Delmarcel - PeerSpot reviewer
Lucas DelmarcelYou will definitely need a continuous monitoring system for your SIEM… more »
6 Answers
Shibu Babuchandran - PeerSpot reviewer
Shibu Babuchandran
Regional Manager/ Service Delivery at ASPL Info Services
May 12 2022

Hi community,

I work as the Regional Manager at a Tech Services company.

Currently, I'm exploring open-source Network Analyzer and Network Configuration managers. 

Which one would you recommend and why?

Faycal Noushi - PeerSpot reviewer
Faycal NoushiHello,  For Network Analyzer, you can use Elastiflow. It's pretty complete… more »
3 Answers

Network Traffic Analysis (NTA) Topics

NTA vs. NDR

Noticeably absent from the term “Network Traffic Analysis” is the word “response.” Network-based solutions should be able to not only investigate and detect threats, but also respond rapidly and effectively. There has been a recent shift in terminology to refer to NDR, or “network detection & response,” which uses NTA but then goes one step beyond, with automated threat response and threat-hunting, using intelligent integration with firewalls, NAC, SOAR, or EDR platforms.

Benefits of Network Traffic Analysis

Benefits of NTA include:

  1. Broad Visibility: NTA tools can monitor and analyze a broad range of communication types, including traditional TCP/IP-style packets, traffic from (or within) cloud workloads, serverless computing instances, and API calls to SaaS apps.
  2. Encrypted Traffic Analysis: Most (more than 70% of) web traffic is encrypted. NTA products offer an accessible method for decrypting network traffic that won’t disrupt data privacy implications. They are able to do this by analyzing the data without actually looking at it.
  3. Comprehensive Baseline: Modern IT environments are constantly changing. NTA tools track behaviors that are unique to a particular entity or to a small number of entities in comparison to the rest of the entities in the environment. As behaviors change, their machine learning baselines are able to evolve in real time. Baselines are even more comprehensive now, due to entity-tracking capabilities, which allow them to understand not only traffic patterns but source and destination entities as well. (For example, normal workstation activity would not be normal activity for a camera.)
  4. Entity Tracking: NTA solutions allow you to track and profile every entity on a network - from devices to users to applications and destinations. Behaviors and relationships are then attributed to each of these entities, which is much more valuable than just a list of IP addresses.
  5. Detection and Response: Because behaviors are attributed to specific entities, there is plenty of context for detection and response workflows. This means security professionals no longer need Instead of having to sift through multiple data sources, security professionals can quickly detect anomalies, track them down, and react accordingly.
What to Look for in an NTA Solution

There are two basic kinds of NTA tools: flow-based tools and DPI (deep packet inspection) tools. Within these, there will be options for historical data storage, software agents, and intrusion detection systems.

Consider the following things when deciding what NTA solution is right for you:

1. Availability of flow-enabled devices. Not all devices are capable of generating the kind of flows required by NTA tools. In contrast, DPI tools accept raw traffic that is vendor independent and found on every network through any managed switch. Network routers and switches don’t require any kinds of special modules or support.

2. The data source: Packet data and flow data come from different sources. Not all NTA tools can collect both. So decide on your priorities before deciding. And then be strategic in choosing what to monitor. Don’t take on too many sources too quickly.

3. Historical data vs. real-time. While historical data can be critical to analyzing past events, not all NTA tools retain this data over time. Have a clear idea of which kind of data is most important to you.

4. Is the software agent-based or agent-free?

5. Full packet capture, complexity, and cost. When looking at DPI tools, consider the cost and expertise required for those that capture and retain all packets versus one that extracts only the critical details and metadata.

Buyer's Guide
Network Traffic Analysis (NTA)
June 2022
Find out what your peers are saying about Darktrace, Auvik, Vectra AI and others in Network Traffic Analysis (NTA). Updated: June 2022.
611,060 professionals have used our research since 2012.