RFprotect System Components
RFprotect Sensor
Key Features
- Purpose-built hardware for performance, range and cost
- Compatible with 802.11 a, b, and g standards
- Simultaneous statistic generation and traffic capture modes
- Rapid adaptive channel scanning to reduce blind spots
- Accessible across the Internet and multiple firewalls
- Low bandwidth requirements for uplinked Ethernet traffic to the RFprotect Server Engine
- Decrypts Wired Equivalent Privacy (WEP) messages for clear traffic analysis with available WEP key
- Supports 802.3af Power over Ethernet (PoE) for operation without a nearby power outlet
- Invisible to wireless hackers
- Easy remote configuration and firmware management
|
 |
RFprotect Sensor Overview
The RFprotect Sensor is a robust appliance that has been purpose-built for wireless activity monitoring. In a typical deployment scenario, multiple sensors are distributed across a physical area to provide 24 x 7 air wave surveillance. Sensors auto-discover and analyze all wireless stations and airborne packets within range, process data, and forward information to the RFprotect Server Engine.
RFprotect Sensors utilize patent-pending technologies that reduce overall system costs. Such cost savings enable affordable sensor deployment even across a large physical area. This makes it possible to create a dense monitoring fabric that weeds out security threats anywhere in the enterprise. RFprotect Sensors leverage Network Chemistry’s revolutionary Shared Constituent Analysis™ architecture to analyze wireless traffic, reduce it to its key indicators, and efficiently backhaul the analyzed data to the central server.
Designed for 802.11
The RFprotect Sensor includes an embedded surveillance agent that has been designed for 802.11 LANs. The agent runs an exceptionally efficient channel scanning algorithm called Channel RapidScan™ across all 802.11 spectrums to minimize monitoring blind spots and provide real-time alerting. The sensor can also decrypt WEP encrypted packets when WEP keys are present and analyze packet protocols up to Layer 7.
The hardware includes a radio port and Ethernet port for communication to the central server. Additional features include support for 802.3af Power over Ethernet (PoE), which greatly facilitates installation in locations where power outlets are unavailable. The RFprotect Sensors are a key reason why the Network Chemistry solution is highly scalable. Because sensor back-haul loads average only 20 Kbps, the devices can be used for the largest and most densely populated WLAN deployments. Plus, RFprotect Sensors can operate in statistical and traffic capture modes simultaneously, facilitating detection and troubleshooting. Technical Specifications
RFprotect Server Engine
Key Features
- Real-time database provides up-to-the-second alert and statistical accuracy
- Parallel multi-method expert detection capability finds anomalous security and operational conditions for greater accuracy and fewer false positives
- CustomProtect™ allows creation of customized signature rules for monitoring enterprise-specific policy compliance
- ODBC/JDBC compliance for integration with enterprise reporting applications
- Cross platform architecture supports Windows and Linux
- Software solution that doesn’t require a dedicated server appliance to perform central analysis

RFprotect Server Engine Overview
Typically deployed on a central workstation in an IT operations center, the RFprotect Server Engine aggregates uplinked traffic from multiple RFprotect Sensors and archives data within two databases: (1) a trending database, used for analyzing security and performance metrics over time, and (2) a real-time database, used to display, on a per-second basis, the system-generated alerts, statistics, and station discoveries. The real-time database also maintains a record of the network’s state, which is used extensively by the expert detection algorithms.
Leveraging innovative Parallel Intrusion Recognition™ technology, the RFprotect Server Engine significantly increases alert accuracy and reduces false positives that often plague other intrusion detection systems. Using this technology, the engine applies multiple recognition algorithms based on signature, statistics, and other sophisticated methods to determine the extent of a security threat or performance problem. The system then correlates the results and generates an alert upon determining that the probability of an anomaly exists. Advanced threat detection algorithms commonly require correlation of real-time network state data to accurately determine whether security threats are real and active.
Modular Expert Alert Architecture
RFprotect's modular architecture enables easy addition of data regarding new attacks to the RFprotect Server Engine expert library. New alerts can be added without upgrading sensor firmware. The engine loads and executes multiple expert detection modules - each with a set of algorithms for detecting specific classes of anomalies. The engine includes modules for detecting rogue devices, station vulnerabilities, intrusion attacks, denial of service (DoS) attacks, and performance anomalies. In addition, Network Chemistry’s unique CustomProtect™ technology enables creation of custom signature rules designed to monitor security policies for your organization’s specific environment.
Real-time Monitoring
Because it maintains the network state in its database, the RFprotect Server Engine can determine in real-time who’s using the wireless network, what they’re doing, and how their activity changes. Information is updated rapidly, enabling live tracking of hacker activity and performance problems. Data can then be used to investigate suspicious activity and thwart hackers before damage occurs. The system also includes historical logging capability for analyzing intruder footprints.
The RFprotect Server Engine records roughly 60 metrics per wireless station. For example, data for configuration and performance include utilization, traffic distribution, signal strength, noise level, data rates, errors, and access point (AP) loading information. RFprotect Server Engine protocol analysis and decode capabilities gather additional detail regarding traffic flows, providing an essential tool for escalated threat assessment and problem troubleshooting.
The RFprotect Server Engine comes in two versions bundled with either a Windows-based graphical user interface (GUI) or a cross-platform (Windows and Linux) command line interface (CLI). The CLI version integrates with third-party security or network operations systems, supports standard integration points such as Syslog, and provides an available application programming interface (API) for direct access to the Server Engine’s rich wireless information base.
RFprotect Client Console
Key Features
- Intuitive Windows-based graphical user interface (GUI)
- Multi-operator access control
- Ability to run as a dedicated application or in the background
- Per second updated displays of WLAN usage
- Historical display (updated in real-time) of detection expert alerts
- Real-time troubleshooting tools with statistical analysis and traffic flow decoding
- Automated reporting and trending
- System configuration and administration
- Also offered as a part of integrated PC application (RFprotect Desktop Console)
RFprotect Client Console Overview
The RFprotect Client Console provides a comprehensive GUI for the RFprotect Server Engine. This Windows-based software offers true plug-n-play capability suitable for most enterprise WLAN deployments. Its intuitive dashboard design and powerful features such as network discovery maps that display detail about individual stations make it ideal for IT managers seeking a superior tool for wireless intrusion protection, performance management, and operational support.
Designed for Ease of Use
The RFprotect Client Console’s intuitive design is so easy to understand that almost anyone can use it. Unlike other consoles that list volumes of raw, non-crucial data, the Client Console provides the right information to do the job efficiently. The first level window provides exception reporting for instant anomaly identification. Network operators can drill down for more detail to resolve problems faster. Events are prioritized by threat level and explained in simple terminology. Initial dashboard windows provide a view of the entire network, but screens with enhanced information regarding stations and packet flows are only a mouse click away. Intelligently organized screen designs and colors focus operators on what’s really important. There’s even an online advisor to guide through the process of interpreting information and taking action.
Look at the full size screens of:
 Main View |
 Alert Control |
 Custom Protect |
 Station Details |
 Trend Reporting |
 Traffic Decode |
Real-Time Updated Displays
Network Chemistry’s innovative technology enables the RFprotect Client Console to display and update wireless security and performance information on a second-by-second basis, even if WLANs are monitored remotely over a wide area network (WAN). Technologies including Channel RapidScan, Shared Continuent Analysis, and the Server Engine's real-time database, make it possible to update dashboard data instantly.
RFprotect Third Party Integration SDK
Key Features
- Support for standard integration points, including SNMP, Syslog, and XML
- Open APIs and software development kits (SDKs) for RFprotect Sensors and the RFprotect Server Engine
- Easily integrates with open source applications like SNORT, Kismet, and Ethereal
- Command Line Interface (CLI) version of the RFprotect Server Engine facilitates access to all available system information
RFprotect was designed with an open architecture that facilitates easy integration with third party security and network operations systems, including those used for network intrusion detection, IP security, and security event, performance, and enterprise network management. You can integrate your existing systems with either the RFprotect Sensor and/or the RFprotect Server Engine.
|