NETSCOUT > Case Studies > Government Agency Battles Cyberthreats With Omnis Cyber Intelligence

Government Agency Battles Cyberthreats With Omnis Cyber Intelligence

NETSCOUT Logo
Company Size
1,000+
Region
  • America
Country
  • United States
Product
  • NETSCOUT® Omnis® Cyber Intelligence
  • Omnis® Cyber Adaptor
  • InfiniStreamNG®
Tech Stack
  • Cybersecurity
  • Network Monitoring
  • Data Analytics
Implementation Scale
  • Enterprise-wide Deployment
Technology Category
  • Analytics & Modeling - Real Time Analytics
  • Cybersecurity & Privacy - Network Security
Applicable Industries
  • National Security & Defense
Use Cases
  • Cybersecurity
Services
  • Cybersecurity Services
  • Data Science Services
About The Customer
The customer is a large-scale government agency that works in collaboration with other government organizations. The agency ensures that data sharing and knowledge transfer occur in a manner that ensures peak operations efficiency. The agency was facing persistent cyberattacks and had gaps in visibility. The Security Operations (SecOps) team's response was slowed by log-intensive cyberattack response processes. The Chief Information Security Officer (CISO) was tasked with enhancing the agency’s cybersecurity profile to address their expanding threat landscape without adding to vendor tool sprawl.
The Challenge
The large-scale government agency was battling persistent cyberattacks and had gaps in visibility. The Security Operations (SecOps) response was slowed by log-intensive cyberattack response processes. The Chief Information Security Officer (CISO) was tasked with enhancing the agency’s cybersecurity profile to address their expanding threat landscape without adding to vendor tool sprawl.
The Solution
The agency chose to implement NETSCOUT's Omnis Cyber Intelligence, an enterprise-wide network threat and risk investigation platform. The solution includes a redundant Omnis Cyber Intelligence server configuration deployed at two Equinix Co-located facilities, with another server operating at their on-premises agency data center. Omnis Cyber Adaptors were configured on ISNG appliances that had been previously deployed at key aggregation points in the network environment to generate smart data for nGeniusONE, thus enabling SecOps to gain enterprise security views from those same locations. The platform stores both network packets and NETSCOUT Smart Data locally on ISNG appliances, enabling Omnis Cyber Intelligence to employ unique indexing and compression techniques to store this data for long durations of time. This data is then used by SecOps to conduct back-in-time analysis, contact tracing, and IP alerting to resolve threats.
Operational Impact
  • The agency was able to remediate Apache Log4j Vulnerability, GeoIP, and persistent cyberattacks.
  • The solution promotes SecOps/NetOps collaboration through a single smart data source for agency analytics.
  • The agency transitioned from a post-incident SecOps approach reliant on use of log files and PCAPs to a proactive program that detects, validates, investigates, and responds to threats without adding to the vendor mix in their security ecosystem.
  • The combination of Omnis Cyber Intelligence and extended security visibility provided by NETSCOUT has enabled SecOps to identify, investigate, and remediate threats in hours or minutes.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.