NetBait Enterprise FAQ

Why should I use NetBait Enterprise?
NetBait Enterprise can be installed on and adapted to any segment of your network. It gives you the flexibility to configure NetBait hosts based on your own setup of actual OS and service configurations. In addition, it provides you with more ways to capture intruder data, while keeping all generated traffic private and under your complete control.

How secure is the NetBait Enterprise Infrastructure?
Multiple layers of security protect NetBait Enterprise infrastructure:

  1. OS and services security for all hardware involved
  2. NetBait service security
  3. Static and dynamic firewall rules
  4. Multiply layers of authentication based on the best encryption currently available
  5. Physical security requirements for administration

What are the hardware requirements for NetBait Enterprise?

There are multiple options in implementation of NetBait Enterprise, all of which will weigh in on determining the hardware requirements. At a minimum, NetBait Enterprise requires the installation and configuration of two servers and three workstations. This infrastructure can be deployed on 10mbps network without Internet connectivity and be capable of creating of 75,000 fake and static objects (up to 15000 objects per NIC, five NICs are used in this example). Minimal dynamic configuration requires two servers and three-plus workstations.

What are the implementation options?

NetBait Enterprise for LAN – to be used inside of your network to produce any number of NetBait hosts based on public and private IP addresses for detection and prevention of inside and outside threats.

NetBait Enterprise for DMZ – for outside protection where every unauthorized access attempt is intruder based. Implementation is based on public IP addresses and NetBait Nodes are used to detect and reroute attacks against your network entry points and public services - routers, proxy servers, gateways, firewalls, and production servers - all to a specific network or a system.

Can you explain what you mean when you refer to "behavior" in NetBait Enterprise?

NetBait Enterprise allows three types of network behavior - static, dynamic and a combination of both:

Static Behavior – they way networks typically behave. It is up to you how to configure any given NetBait Host. You select the operating system, the services, and the security level. In this example of behavior, your changes are static, thus your configuration will remain the same until you manually change it through NetBait’s web-based interface. The same static settings can be applied to thousands of IP addresses concurrently, if necessary, to create virtual “black holes” for an intruder. Here, every attempt at unauthorized access sounds an alarm and shuts the door.

Dynamic Behavior – Dynamic behavior is used not only to create fake nodes on your networks, but also to make those nodes more "appealing" to an intruder. Utilizing Dynamic Behavior, not only will your network look "busy," it will also be completely unpredictable to any intruder who decides to scan it. That is, the picture that an intruder sees will change in real time and without your direct involvement. In effect, your network will look like a kaleidoscope of operating systems and services. Even if an intruder finds the key to break in, he will not be able to inflict any damage on the network because it will reappear as something completely new.

Static & Dynamic Combined – Provides for a particular IP address to employ static behavior while another employs dynamic. This simply speaks to the inherent flexibility of NetBait Enterprise.

How can I perform administation tasks in NetBait Enterprise?

Local Administration ensures that only trusted personnel can change your NetBait Enterprise configuration and options. It requires the admininstrator to be connected to a specific NIC, and only accepts requests from a specific private IP address. In addition, it requires the correct authentication.

Remote Administration is available through NetBait Enterprise's Web interface. Remote access requires that a local adminstrator implement a static firewall before a connection can be accomplished. This feature can be useful if your NetBait Enterprise serves multiple networks and is used by multiple administrators.

What does it take to support NetBait Enterprise internally?
Depending on the purpose of your NetBait Enterprise infrastructure, support is usually limited to periodic attention by a single adminstrator. Once NetBait is configured, it simply does its job. Even reporting can be turned off or re-directed to seperate log server to minimize adminstrator attention.

NetBait Demo

Products

Support FAQ

Brochures and White Papers