Firewall Traffic Analysis (FTA) Application
Starlight aggregates, parses and normalizes traffic log data from multiple Firewalls, which can be from different vendors such as Check Point, Palo Alto Networks, Fortinet, and Sophos.
Supercharge Firewalls with intelligence through machine learning, built-in threat intelligence and integrated applications
Supercharge Firewallsa
Leverage existing Firewall investments to collect security data without deploying dedicated sensors
Apply Machine Learning to Firewall data in order to see any anomalies
Detect potential Firewall policy mis-configurations, compromised and malicious users and their abnormal traffic to/from the Internet
Firewall traffic logs are transformed into Interflow™ records through normalization and enrichment.
Fuse context with threat intelligence and reveal additional detection’s such as Geo Fencing or communication with known malicious actors
Cost-effectively store firewall traffic logs for forensics and threat hunting
Leverage closed-loop automated workflow to block attackers through Firewall APIs
Second set of eyes
Dedicated Stellar Cyber security sensors deployed behind the Firewall detect what’s missed
Deep packet inspection (DPI) engines integrated in these security sensors generates richer set of meta data
Detect potential Firewall policy misconfigurations
Integrated NTA and UBA detections also provide a rich workbench for security personnel
Detect DGA and DNS tunneling through machine learning and additional detection’s across the cyber kill chain, such as Ransomware
Leverage closed-loop automated workflow to block attackers through Firewall APIs
Key Features
Firewalls are for Enforcement
Firewalls are the first line of defense in any network security framework. The primary purpose is to inspect network traffic in real time and determine whether to allow or block specific traffic based on a set of security rules defined by administrators. The traffic volume can be significant and legacy Firewalls have limited resources in terms of processing power and storage size. Thus the Firewall has limited intelligence itself and it is usually optimized only for policy enforcement.
Firewall Traffic Analysis [FTA]
Starlight aggregates, parses and normalizes traffic log data from multiple Firewalls, which can be from different vendors such as Check Point, Palo Alto Networks, Fortinet, and Sophos. Interflow records create context for these logs by fusing together many other data sources like Threat Intelligence, Geolocations, host or domain names, and user names. Both real-time and historical advanced analysis of contextual data are performed through machine learning.
Starlight performs anomaly detection through machine learning including deep learning. Starlight can detect mis-configuration of Firewalls, which can be deadly. One reason that CapitalOne was hacked was because of Firewall misconfigurations. Starlight can expand Firewall rules into dimensions such as geo-location, reputation, hostnames, etc. besides IP address and user names.
Integrated SOAR
Starlight is a software application architected with container-based micro-services and a data lake for big data. It processes and stores large amount of Firewall logs turned Interflow records, and scales for more processing power and available storage capacity. Security analysts can perform Google like search on Interflow records for forensics and threat hunting. Respond to detected advanced threats by blocking attackers’ IP through API calls to Firewalls. These interactions can be done either manually or automatically.
Related solutions
Entity Behavior Analytics (EBA) Application
Stellar Cyber’s Open XDR provides a single unified view, automatically and constantly discovering new assets, identifying…
View details ↗
Next Gen SIEM Application
Unlike legacy SIEM, Starlight leverages advanced techniques like machine learning for detection of unknown threats and…
View details ↗
Stellar Cyber for MSSPs
Stellar Cyber for MSSPs Multi-Tenancy The industry’s first multi-tenant, AI-driven breach detection platform for MSSPs AI-Driven…
View details ↗
Stellar Cyber For SIEM
Stellar Cyber For SIEM With Starlight for SIEM, you can gain more visibility and utility out…
View details ↗
Stellar Cyber For Private Cloud
Stellar Cyber For Virtualized Environments Lightweight application that consumes less than 5% of the environments total…
View details ↗
Stellar Cyber For Public Clouds
Stellar Cyber For Public Clouds AI-Driven Security for Public Clouds Do you know if your cloud…
View details ↗Stellar Cyber For Containers
Stellar Cyber For Containers The industries first AI-Driven Breach Detection System for container workloads AI-Driven Security…
View details ↗Related articles
Redis chính thức trở thành công cụ lưu trữ dữ liệu số 1 cho AI Agent
Built for devs. Trusted by devs. Báo cáo Stack Overflow Developer Survey 2025 vừa công bố đã khẳng…
Read article ↗
It’s official: Redis is the #1 AI agent data storage tool
Built for devs. Trusted by devs. The 2025 Stack Overflow Developer Survey is out, and devs worldwide have spoken. They…
Read article ↗
Data – The Foundation for National Digital Transformation and the Strategy for the Fourth Industrial Revolution
Data – The Foundation for National Digital Transformation and the Strategy for the Fourth Industrial Revolution Hanoi, August…
Read article ↗
Dữ liệu – Nền tảng phát triển chuyển đổi số quốc gia và chiến lược quốc gia về cách mạng công nghiệp 4.0
Dữ liệu – Nền tảng phát triển chuyển đổi số quốc gia và chiến lược quốc gia về…
Read article ↗Turn technology into business value.
Connect with Nessar experts to discuss architecture, implementation and the right roadmap for your organization.