Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

PacketMotion PacketSentry 2.0.3: Page 4 of 4

PacketMotion can even verify that the last days of an employee were not spent performing malicious acts on the network. I created a report for two different weeks of data and easily compared the differences in network traffic and application usage. I could see there was more IM activity and encrypted connections in the last week than there had been in previous weeks. A company could easily re-create this process to verify that access was not made to files outside of the former employee's purview and ensure that no data was altered or deleted.

PacketSentry is a great product to fill in the gaps where IDS and network-flow monitoring fall short--provided your environment uses Active Directory. It assists with the who, where, what and when necessary to investigate network and personnel issues. Note, though, that it's not a replacement for a network forensic device as it does not capture the network traffic to disk for in-depth review.

John H. Sawyer is a network security engineer at the University of Florida and a GIAC Certified Firewall Analyst and Incident Handler. Write to him at [email protected].