Go to Main Contents
⁇ Return to the product centre

NATHHEL_LOG_AUDIT and cross-border communication detection

Log Audit & Traffic Detection

Focusing access, session, authentication and traffic leads on retention, query, analysis and alarm

The independent NATSHEL_LOG_AUDIT system is aimed at log collection, central storage, retrieval, statistics and traceability; cross-border VPN, proxy and unusual outreach leads can be analysed in conjunction with DPI, flow characteristics, IP attribution and behavioural models where export flows are visible.

PRODUCT CAPABILITY MAP

LOG INSIGHT

READY
Log Audit & Traffic Detection Core competencies
01

Multi-source log capture

02

Central storage and retrieval

03

Flow and time delay analysis

04

Cross-border leads identification

• Product positioning

How products access existing networks

The data, such as authentication, session, DNS, NAT, URL and network traffic, enter the collection and processing chain for use in search, statistics, alarms and traceability after structured storage.

Value of products

Focusing access, session, authentication and traffic leads on retention, query, analysis and alarm

01

Data sources

  • Authentication / Session
  • NAT / DNS / URL
  • Network and security equipment
  • Export mirror flow
02

Collection and processing

  • Log Collection
  • Field Parsing
  • Identity association
  • Incident monitoring
03

Storage and analysis

  • Central Storage
  • Multiple Retrieval
  • Trends and TOP analysis
  • Flow and Time
04

Output and Response

  • Query and Export
  • Large Screens and Reports
  • Rules alert.
  • Backup

• Product interface and deployment

From network posture to cross-border sessions, support drilling and association traceability

The platform receives mirror traffic, session logs and certified logs, forming multi-dimensional views of users, accounts, source addresses, target addresses, domain names, application protocols, operators and place of belonging.

NATHHEL_CROSS_BORDER_TRAFFIC workstation to show trends, source IP, target IP and domain name statistics
Cross-border monitoring workstationCentralize VPN flows, VPN applications, offshore IPs and trends changes and support the continued drilling from source IPs, target IPs and domain names.
Deployment of the Cross-Border Traffic Detection system
♪ Bystanders gathering the conference talk ♪The image flow is received on the side roads of the core or exit without changing the original transmission path and identifying results for analysis, alarm and traceability.
Cross-border testing, certification log association, regulatory reporting and road blockage synergizing
Identity association and association disposalLinks the log to the account number; the detection platform is responsible for identifying and recording, and blocking of executory devices such as routers, firewalls, etc.

Multidimensional traffic analysis

View traffic, speed and timing by user, account, agreement, target, region, operator, interface and group.

Cross-border and VPN recognition

Combining DPI, encryption traffic features, application of fingerprints and threat intelligence to identify VPNs, proxy and offshore communication leads.

Log search and evidence

Retains records such as URL, DNS, NAT sessions, authentication and virtual identity to support queries by five-digit and account number association.

Alerting to work with third parties

The alerts are issued and sent on time, simultaneously and with communication features and can be forwarded to the enterprise ' s micro-mail, nails, mailboxes or third party platforms.

:: Functional characteristics

Core competencies around Log Audit and NETSHELL_CROSS_BORDER_TRAFFIC products

The key capabilities of the product in connection, management, strategy, operation and transport are used to help you quickly understand its value and orientation.

Multi-source log collection

01

Collects accreditation, session, NAT, DNS, URL, equipment and application logs.

  • Network and security equipment
  • Authentication and user records
  • Access to the meeting threads

Structured storage and retrieval

02

Queries and export results according to time, user, IP, destination, protocol etc.

  • Single / Grouping Conditions
  • Second filter of results
  • Distributed Storage Options

Flow Visualization

03

Flow and connectivity trends are viewed from user, application, target, geographic and operator dimensions.

  • TOP User/ Application
  • Flow flow
  • Parallel development and delayed trends

Identity and behavioural traceability

04

Supports the location of events by linking user authentication, IP, sessions to access logs.

  • Authentication records
  • Five-dollar group session
  • DNS, URL and NET threads

Cross-border and VPN threads

05

Identification of cross-border applications, agency agreements, offshore IPs and unusual communication modes when deployment conditions are met.

  • DPI / TLS Fingerprints
  • Flow behaviour models
  • IP Attribution and Risk Threads

Alert and running analysis

06

Configures the time delay, simultaneous or event rules and exports alarms via a control table or an interface.

  • Threshold and Conditional Alert
  • System active
  • Statistical Reports and Large Screens

04 Deployment path

From current network conditions to full operation

The underlying conditions are checked before access and validation is progressively achieved to reduce the operational risks associated with one-time switching.

  1. 1

    Clear log range

    Identify compliance targets, data sources, fields, retention cycles and query scenarios.

  2. 2

    Designing the collection links

    Planning equipment logs, authentication data and mirror traffic collection location and bandwidth.

  3. 3

    Configure Storage and Rules

    Design single machines or distributed storage by data volume and establish query and alarm rules.

  4. 4

    Verifying a retroactive closed loop

    Authentication of identification, retrieval, export, alarm and disposal processes using typical events.

05. Applied scene

Which projects deserve to be highlighted

Web projects with logs, access back-to-back, NATSHEL_CROSS_BORDER_TRAFFIC or unusual outreach management needs.

Colleges and campuses

Centralize user access and network access leads to support network operations and security analysis.

Network of Government and Enterprise

Collect equipment, security and access logs to support queries, reports and audits.

Operating networks

Distributive storage, flow analysis and event traceability for larger log volumes.

Cross-border communication detection

VPN, proxy and unusual outreach leads are identified when export flows are visible.

Description of deployment

The log retention range, fields, storage cycle and performance are accounted for by data source, flow and hardware configuration. Cross-border testing is primarily capable of identifying, recording, analysing and alerting, and does not amount to a full interception or compliance conclusion; identifiable objects and accuracy depend on encryption, deployment location, feature library, model version and field validation.

Product information

In-depth knowledge of product and configuration methods

Download product presentations, white papers and operations manuals to gain a better understanding of system architecture, functionality configuration and usage.

View all product information

Next

Need more information on Log Audit and Cross-Border Traffic Detection?

Tell us about the use of scenes, user size and current network patterns, first to determine how products match the existing network, then to discuss models, interfaces and scope.

Obtain preliminary project judgements
Access Program I'll be right back. Telephone counselling