Collecting Information

Collecting Information

Introduction

When an intruder attempts to break into your system, RealSecure Desktop Protector can

 

track the intruder’s activities. You can use this information to determine what an intruder

 

did to your computer. This section explains how to gather and use this information.

Back Tracing

Desktop Protector can back trace each intrusion to determine where it originated. You can

 

tell Desktop Protector to seek information from the originating computer itself or from

 

points the packets passed through on the way to your computer.

 

When Desktop Protector back traces an intruder, it attempts to gather the IP address, DNS

 

name, NetBIOS name, Node, Group name, and MAC address. Skilled intruders will often

 

block Desktop Protector from acquiring this information.

 

To set up back tracing, see “Introduction” on page 50 and “The Back Trace Tab” on

 

page 76.

Evidence files

RealSecure Desktop Protector can capture network traffic attributed to an intrusion and

 

place that information into an evidence file. Desktop Protector captures and decodes each

 

packet coming into the system, so it can generate files that contain detailed information

 

about the intruder's network traffic.

 

To an experienced network engineer, evidence files show exactly what the intruder did or

 

attempted to do. Because evidence files provide proof of the attacker's activities, this can

 

be very useful to law enforcement or legal counsel in tracking criminal intruders.

 

For information about setting up evidence gathering, see “Collecting Evidence Files” on

 

page 52.

Packet log files

Packet logging records all the packets that enter your system. This can be useful if you

 

need more detailed information than evidence logs contain. Packet logs can become very

 

large and use considerable hard disk space. However, if you are experiencing repeated

 

intrusions on a system, packet logging can help gather additional information about

 

activity on the system.

 

For information about setting up packet logging, see “Collecting Packet Logs” on page 54.

11

Page 19
Image 19
Internet Security Systems 3.5, Desktop Protector Collecting Information, Back Tracing, Evidence files, Packet log files

3.5, Desktop Protector specifications

Internet Security Systems Desktop Protector 3.5 is a robust cybersecurity solution designed to provide comprehensive protection for personal computers and workstations. As cyber threats continue to evolve, this software aims to protect users against malware, phishing, and other malicious attacks with its advanced feature set and technologies.

One of the main features of Desktop Protector 3.5 is its real-time scanning capability. It constantly monitors files and applications on the system for any signs of malicious activity. This proactive approach ensures that harmful software is detected and neutralized before it can execute, providing users with peace of mind as they navigate the internet or access sensitive information.

Another significant feature is the integrated firewall. This firewall effectively controls incoming and outgoing traffic, offering an additional layer of protection by blocking unauthorized access to the user's network. Users can configure the firewall settings to tailor their security level according to their specific needs, ensuring flexibility and adaptability.

Desktop Protector 3.5 also incorporates advanced heuristic analysis technology. Unlike traditional antivirus solutions that rely primarily on known malware signatures, heuristic analysis examines the behavior of files and applications. This allows the software to identify and block new or unknown threats based on their potential behavior, significantly enhancing its detection capabilities.

The software's user-friendly interface makes it accessible to users of all technical backgrounds. With straightforward navigation and intuitive controls, even those who are not tech-savvy can efficiently manage their security settings and monitor their system's health.

Moreover, Desktop Protector 3.5 offers automated updates, ensuring that the security software remains current with the latest threat definitions and security patches. This feature guarantees that users are always safeguarded against emerging threats without requiring manual intervention.

Another noteworthy characteristic is its low system impact; Desktop Protector 3.5 is designed to operate seamlessly in the background. Users can work, play, or browse the internet without experiencing noticeable lag or performance issues, making it an ideal security solution for both personal and professional environments.

With its combination of powerful features, advanced technologies, and user-centric design, Internet Security Systems Desktop Protector 3.5 stands out as a reliable choice for anyone seeking to enhance their cybersecurity posture in an increasingly digital world.