{"product_id":"hpe-introspect-pp-1000-network-securityfirewall-appliance-jz262a","title":"HPE IntroSpect PP 1000 Network Security\/Firewall Appliance - JZ262A","description":"\u003cdiv\u003e\n\u003ch4\u003e\u003cstrong\u003eGeneral Information\u003c\/strong\u003e\u003c\/h4\u003e\n\u003cli\u003eManufacturer: Hewlett Packard Enterprise\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eManufacturer Part Number: JZ262A\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eManufacturer Website Address: http:\/\/www.hpe.com\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eBrand Name: HPE\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eProduct Line: IntroSpect\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eProduct Model: PP 1000\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eProduct Name: IntroSpect PP 1000 Network Security\/Firewall Appliance\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eMarketing Information: \u003cb\u003eUSER AND ENTITY BEHAVIOR ANALYTICS\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003eAruba's User and Entity Behavior Analytics (UEBA) solution, Aruba IntroSpect, detects attacks by spotting small changes in behavior that are often indicative of attacks that have evaded traditional security defenses. Aruba IntroSpect integrates advanced AI-based machine learning (ML), pinpoint visualizations and instant forensic insight into a single solution, so attacks involving malicious, compromised or negligent users, systems and devices are found and remediated before they damage the operations and reputation of the organization.\u003cbr\u003e\u003cbr\u003eWith a Spark\/Hadoop platform, IntroSpect uniquely integrates both behavior-based attack detection and forensically-rich incident investigation and response at enterprise scale.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eWHAT WE DETECT: SECURITY ANALYTICS USE CASES\u003cbr\u003e\u003cbr\u003e\u003c\/b\u003eIntroSpect provides 100+ supervised and unsupervised machine learning models focused on detecting targeted attacks at each stage of the kill chain:\u003cbr\u003e \u003cul\u003e \u003cli\u003eAccount Abuse\u003c\/li\u003e \u003cli\u003eAccount Takeover\u003c\/li\u003e \u003cli\u003eCommand and Control\u003c\/li\u003e \u003cli\u003eData Exfiltration\u003c\/li\u003e \u003cli\u003eLateral Movement\u003c\/li\u003e \u003cli\u003ePassword Sharing\u003c\/li\u003e \u003cli\u003ePrivilege Escalation\u003c\/li\u003e \u003cli\u003eFlight Risk\u003c\/li\u003e \u003cli\u003ePhishing\u003c\/li\u003e \u003cli\u003eRansomware\u003c\/li\u003e \u003c\/ul\u003e \u003cb\u003eACCELERATED INVESTIGATION \u0026amp; RESPONSE\u003cbr\u003e\u003cbr\u003eFrom SysAdmins to Systems to Sensors - Providing Instant Visibility\u003cbr\u003e\u003cbr\u003e\u003c\/b\u003eIntroSpect Entity360 is key to reducing the time and effort required to understand, diagnose and respond to an attack. Entity360 provides a comprehensive security profile with continuous risk scoring and enriched security information - analysts would otherwise spend hours or days searching for and compiling months and years of security data down to the packet level. Entity360 provides:\u003cbr\u003e \u003cul\u003e \u003cli\u003eProfiles for users, systems and devices\u003c\/li\u003e \u003cli\u003eAccess by SIEM, NAC systems, etc. via an open API\u003c\/li\u003e \u003cli\u003ePre-packaged incident response playbooks\u003c\/li\u003e \u003cli\u003eCustomer-measured 30 hours\/investigation savings\u003c\/li\u003e \u003cli\u003eAutomatic detection of other entities impacted by the attack\u003c\/li\u003e \u003c\/ul\u003e \u003cb\u003eTHREAT HUNTING\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003eProactive threat hunting is easily accomplished with a powerful query interface, without the overhead of finding, searching, and summarizing isolated data stores.\u003cbr\u003e \u003cul\u003e \u003cli\u003eRich analytics to test threat hypotheses across any timeframe\u003c\/li\u003e \u003cli\u003eAutomated search of historical data using IOC's from STIX and custom threat feeds\u003c\/li\u003e \u003cli\u003eVisualizations to highlight anomalies and significant interactions\u003c\/li\u003e \u003cli\u003eSignificant activity monitored and tagged to assist with both hunting and investigations\u003c\/li\u003e \u003c\/ul\u003e \u003cb\u003eDATA SOURCES\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003eThe IntroSpect platform processes the broadest range of data sources, including:\u003cbr\u003e \u003cul\u003e \u003cli\u003eVPN, FW, IPS\/IDS, Web proxy, Email logs\u003c\/li\u003e \u003cli\u003eNetFlow\u003c\/li\u003e \u003cli\u003ePackets\u003c\/li\u003e \u003cli\u003eDNS logs\u003c\/li\u003e \u003cli\u003eActive Directory logs\u003c\/li\u003e \u003cli\u003eDHCP logs\u003c\/li\u003e \u003cli\u003eExternal threat feeds\u003c\/li\u003e \u003cli\u003eAlerts from 3rd party security infrastructure\u003c\/li\u003e \u003c\/ul\u003e \u003cb\u003eDEPLOYMENT OPTIONS\u003c\/b\u003e\u003cbr\u003e \u003cul\u003e \u003cli\u003eOn-premise VM or appliance for Packet Processor\u003c\/li\u003e \u003cli\u003eAWS or on-premise deployment for Analyzer\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003e\u003cb\u003eKEY INTEGRATIONS\u003c\/b\u003e\u003c\/p\u003e \u003cul\u003e \u003cli\u003eArcSight\u003c\/li\u003e \u003cli\u003eAruba ClearPass\u003c\/li\u003e \u003cli\u003eBlue Coat\u003c\/li\u003e \u003cli\u003eCheckpoint\u003c\/li\u003e \u003cli\u003eCisco\u003c\/li\u003e \u003cli\u003eFireEye\u003c\/li\u003e \u003cli\u003eForcepoint\u003c\/li\u003e \u003cli\u003eFortinet\u003c\/li\u003e \u003cli\u003eGigamon\u003c\/li\u003e \u003cli\u003eIBM QRadar\u003c\/li\u003e \u003cli\u003eInfoblox\u003c\/li\u003e \u003cli\u003eIXIA\u003c\/li\u003e \u003cli\u003eJuniper\u003c\/li\u003e \u003cli\u003eMcAfee (as in proxy server)\u003c\/li\u003e \u003cli\u003eMicrosoft\u003c\/li\u003e \u003cli\u003ePalo Alto Networks\u003c\/li\u003e \u003cli\u003eSplunk\u003c\/li\u003e \u003c\/ul\u003e\n\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eProduct Type: Network Security\/Firewall Appliance\u003cbr\u003e\n\u003c\/li\u003e\n\u003ch4\u003e\u003cstrong\u003eTechnical Information\u003c\/strong\u003e\u003c\/h4\u003e\n\u003cli\u003eFirewall Protection Supported: \u003cul\u003e\n\u003cli\u003eNetwork Attack Detection\u003c\/li\u003e\n\u003cli\u003eAnti-phishing\u003c\/li\u003e\n\u003cli\u003eThreat Protection\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cbr\u003e\n\u003c\/li\u003e\n\u003ch4\u003e\u003cstrong\u003eManagement \u0026amp; Protocols\u003c\/strong\u003e\u003c\/h4\u003e\n\u003cli\u003eManageable: Yes\u003cbr\u003e\n\u003c\/li\u003e\n\u003ch4\u003e\u003cstrong\u003eWarranty\u003c\/strong\u003e\u003c\/h4\u003e\n\u003cli\u003eSupport\/Service Duration: 1 Year\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/div\u003e","brand":"Hewlett Packard Enterprise","offers":[{"title":"Default Title","offer_id":50319632564581,"sku":"2CC759","price":12804.48,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0885\/4392\/0485\/files\/1041217246.jpg?v=1787377275","url":"https:\/\/itosolutions.net\/products\/hpe-introspect-pp-1000-network-securityfirewall-appliance-jz262a","provider":"ITO Solutions, Inc.","version":"1.0","type":"link"}