New features and improvements in PT ISIM proView Sensor / netView Sensor version 3.3
1. New features
With the new version of PT ISIM pro/netView Sensor, you can track violations that is, deviations of node characteristics from the recommended values.
In version 3.3, the Events page has been redesigned. The main changes are as follows:
- You can now configure the look of the event table;
- The filter by time has been improved;
- The new version provides enhanced capabilities for downloading PCAP files.
File extraction from traffic
The new version of PT ISIM pro/netView Sensor can extract files of certain types (such as archives, executable files, device configuration files, and office application files) from processed traffic and store them.
Support for new protocols
PT ISIM pro/netView Sensor 3.3 supports analysis of the OPC UA, CODESYS V2, and CODESYS V3 protocols.
Detection of new incidents
PT ISIM pro/netView Sensor 3.3 has rules for detecting the following:
- Incidents in traffic over the CODESYS V2 and CODESYS V3 protocols;
- Attempts to exploit URGENT/11 vulnerabilities in the VxWorks operating system;
- Attempts to exploit vulnerabilities in Cisco Prime Infrastructure (PI), Cisco Evolved Programmable Network (EPN), and Sophos Web Appliance.
Improved installation process
The product installation process has been improved. The steps performed by the PT ISIM pro/netView Sensor installation script are now independent from each other: within each step, the script installs a certain component and performs a set of related actions.
Connection storage time
Starting with version 3.3, connections are stored in PT ISIM pro/netView Sensor for 24 hours.
Extended list of node types
To ensure more accurate inventory, the list of possible node types has been extended in version 3.3. It now includes new values: router, safety PLC, firewall, KVM switch, and proxy server.
Detection of new nodes
The algorithm for detecting new nodes in an analyzed network has been improved. In version 3.3, a new node is registered for each new combination of an IP address and a MAC address (or only for a MAC address if there is no IP address).
Removal of the ptisim-rester and ptisim-broker-worker services
In PT ISIM pro/netView Sensor 3.3, the ptisim-rester and ptisim-broker-worker services have been removed. Their functions are now performed by ptisim-core.
Support for ERSPAN
The new version supports analysis of ERSPAN tunnels, making it possible to detect and analyze data encapsulated in such traffic.
Fault tolerance of the modeling service
The fault tolerance of the modeling service (ptisim-model-service-ng) has been improved.
For additional details, see the PT ISIM proView Sensor / netView Sensor Release Notes.