Login | Help | Retrieve Data

Packet Capture

Home > Products > Packet Capture

Full Packet Capture Appliances

Standalone GbE & 10G network appliances for full packet capture and network monitoring

Experts agree – it is critical to secure IT infrastructure and organizations that deploy continuous packet capture gain a key component towards securing their networks: comprehensive real-time and historical network visibility. Network visibility provides the necessary operational intelligence for investigators to quickly and thoroughly respond to network incidents, tracing back and reconstructing every single cyber-event as it unfolded on the network, rather than trying to cobble together evidence and a rough timeline based on incomplete, fragmented data.

Full packet capture (aka packet sniffing) also provides the data necessary to ascertain an organization's actual cyber-threat environment, as well as pinpoint vulnerabilities and points of entry, in the case of a breach. Knowing the full extent and progression of a breach is the best way to conduct quick and relevant breach mitigation and reduce the time to resolution of any network event.

Capture Every Packet, Every Time

IPCopper full packet capture appliances (aka packet sniffers) capture and store IP activity in full, providing current and historical IP activity in its entirety and ensuring that when you need to know what happened on your network, the data is there. This type of full packet capture enables effective incident response and comprehensive network forensics investigations into security breaches, hack attacks and other network incidents based on complete and accurate data.

IPCopper network devices are standalone, fully automatic, Ethernet/IP, high memory capacity gigabit and 10G packet capture appliances. Truly no configuration is required — simply connect power and Ethernet cables and the unit is ready to go. Either connect the unit inline (aka, pass-through; the unit automatically acts as its own network tap) or to a SPAN port. When connected as pass-through, IPCopper packet capture appliances introduce less than 1 ms (<0.001 sec) of latency and will not affect network flow or topology.

Integral data security features keep captured data private. Operating under a cloak of electronic invisibility (no IP or MAC address), IPCopper packet capture appliances cannot be addressed nor detected like traditional network devices. You can access and download data either locally or remotely using included command-line utility individually mated to each IPCopper. For additional security, all captured data is encrypted using a 20,000 bit external key.

Capabilities

IPCopper packet capture appliances record web browsing sessions, emails, IM chats, FTP sessions and all other Ethernet-based transmissions, communications and commands in full, capturing both packet headers and payloads. They are ideal for:

  • Detecting and preventing electronic theft and unauthorized data / network access.
  • Cyber-surveillance
  • Making carbon copies of e-mails and other electronic communications.
  • Logging access and transmissions to and from data servers, file servers, credit card servers or other databases.
  • Monitoring the internet use and network activities of employees.
  • Identifying and troubleshooting network problems.
  • Benchmarking servers and networking equipment.
  • Diagnosing virus, spyware and malware infestations.
  • Facilitating thorough forensic analysis and quick incident response.
  • Tracking data leakage.
  • Ascertaining the extent of compromised data and liability in the case of a breach.

Downloading the captured packets from IPCopper is easy, fast and convenient: simply use the included command-line utility and input the desired date and time range on your computer. You will immediately receive a PCAP file of the information requested, which you can use with your favorite packet analysis tools.

IPCopper models

Memory Capacity
Peak Capture Speed
Min. Sustained Capture Speed
Type
Min. Sustained Packet Rate (packets/second)

USC1030

1 TB
1 Gbps
400 Mbps
forensic
150,000

USC2030

2 TB
1 Gbps
400 Mbps
forensic
150,000

USC4060

4 TB
1 Gbps
400 Mbps
continuous
165,000

USC10G08

8 TB
10 Gbps
2 Gbps
continuous
1,000,000

USC10G24

24 TB
10 Gbps
6 Gbps
continuous
1,000,000

All current IPCopper packet capture appliances feature the following:

  • Electronically invisible — no IP or MAC address
  • Autonomous operation, no configuration required
  • Jumbo frames support, up to 9KB
  • Flow control
  • Tamperproof case

IPCopper: Achieving Data Security through Knowledge