PACKET BLACK HOLE
STANDARD OF NETWORK FORENSIC : PACKET BLACK HOLE ≫JAPANESE ≫Net Agent

Specification

  
model PBH-SQ1a PBH-NR1 PBH-NE2
photo PBH-NQ1 PBH-IR1 PBH-NE2
CPUIntel CPU x 1 Intel CPU x 1 Intel CPU x 2
memory 512MB 1GB 2GB(Reg. ECC)
HDD 750GB(SATA) 500GB (max:6TB) 143GB (max:4.2TB)
network cark 10/100/1000Mbps correspondence
Gigabit supports only with cluster specifications
case cube type 2U rack mount type 3U rack mount type
size 210(W) x 325 (D) x 220 (H) mm 426(W) x 650 (D) x 89 (H) mm 450(W) x 647 (D) x 132 (H) mm
number of the assumed users under 50 users 50-500 users 500-2000 users

* The number of the assumed users means just a round number by normal usage. By a usage, environment and purpose, it can process more large quantities.

Option

model PBH-SQ1a PBH-NR1 PBH-NE2
Additional option PBH-OVS
Virus scan
  PBH-500GS
500GB Additional disk
PBH-S143G
143GB Additional disk
  PBH-1000GS
1000GB Additional disk
PBH-S300GS
300GB Additional disk
  PBH-SRD3750GB
External RAID 3750GB
PBH-USBCDROM
USB Portable CD-ROM Drive (* Maintenance use only)

※The specification might be changed without a previous notice.

Main function

Data reproduction HTTP/1.1, HTTP/1.0, HTTP PROXY, SMTP, POP3, Attachment
Decovering Data Invasions, Attacks Illicit Mail, Entries on Web Site, Abnormal System
Securities Stealthness, Password, SSL, MAC Address Authorization, Multi-User, Private Mail
Analysis HTTP Request HTTP Responce, HTTP PROXY Request, Web Password, SMTP Responce, POP3 Request
Mail attached file Web Mail attached file, Cookie,grep
Packet analysis(corresponds to 260 protocols) Details of packet, Communication statistics, Computer name scanning, DNS scanning, Full-text search
Categories URL,Mail Conditions, Intrusion, Content judgment classification
Options Roles and load-balancing with cluster, Virus detection, Backup with tape

Specification of full-text search

Main function Content
Object data Attached file, WebPOST (bulletin board writing and Web Mail Sending, etc.), and Web data.
File format Word, Excel, PowerPoint, PDF, HTML, ZIP, LHA, tar.gz, TGZ, text file
Correspondence language Japanese, English, French, German, Chinese Taige, Chinese Shigetaige
Extendibility Corresponds to clustering
Limitation of number of documents Depends on the size of the hard disk(The number of documents of 1〜10 million is assumed)
Response performance Within one second
Search condition For AND retrieval
Category dictionary More than 2400 Japanese words
Generation management The oldest index set is deleted by the generation management. The setting that stops the data taking is also possible.

Recording Time

It is rare to use a band more than 1/5. You may not have a problem if you decide your disk's capacity with the recording time in the case of using average about 1/5 band. If your disk is full, "PacketBlackHole" delete the oldest data automatically.

Actual flowing quantity

80G143G830G2400G3750G7500G
128kbps 31.6 days 59.3 days 328 days 1002 days 1620 days 3443 days
1.5Mbps 2.7 days 5 days 28 days 85 days 138 days 276 days
10Mbps 0.4 days 0.8 days 4.2 days 13 days 20 days 41 days
100Mbps 0.04 days 0.08 days 0.17 days 1.3 days 2.0 days 4.2 days

When the use rate of the band is about 1/5 on the average

80G143G830G2400G3750G7500G
128kbps 158 days 297 days 1641 days 5010 days 8100 days 16217 days
1.5Mbps 13.5 days 25 days 140 days 428 days 691 days 1384 days
10Mbps 2.0 days 3.8 days 21 days 64 days 104 days 207 days
100Mbps 0.2 days 0.4 days 2.1 days 6.4 days 10 days 21 days


Copyright(c) NetAgent Co.,Ltd. 2002
for More Information : info@netagent.co.jp