TrustRadius: an HG Insights company

Flowmon ADS

Score9.1 out of 10

1 Reviews and Ratings

What is Flowmon ADS?

Flowmon Anomaly Detection System (Flowmon ADS) by Kemp is a network security solution that analyzes network traffic from multiple perspectives to counter malicious behaviour and cyberattacks. By using a combination of detection methods, including machine learning, adaptive baselining, heuristics, behaviour patterns, and signatures, context-rich visualization and reporting, ADS provides SecOps teams with capabilities for incident detection, handling, analysis and response.

Media

Threats are detected instantly and automatically.
Behavior pattern recognition detects threats in their infancy.
Machine learning and other algorithms combined to deliver accurate insights.
Flowmon ADS is a common grounds for collaboration between NetOps and SecOps on incident resolution.
The solution integrates with event logging, ticketing and incident response systems.
Incident visualization for instant remediation.

1 / 6

Customizable anomaly detection solution with excellent scalability capabilities

Pros

  • Kemp Flowmon ADS provides a large set of essential detections out of the box, which allows us to quickly acquire an awareness of potential problems in the monitored network.
  • Custom configuration, filters, and false-positive flagging make the system highly customizable for diverse environments.
  • Powerful dashboards make summaries and reporting a breeze.

Cons

  • Multi-license policy
  • Outdated GUI
  • Limited use of AI methods

Most Important Features

  • Flowmon ADS provides a large set of essential detections out of the box, which allows to quickly acquire an awareness of potential problems in the monitored network.
  • Custom configuration, filters, and false-positive flagging make the system highly customizable for diverse environments.
  • Powerful dashboards make summaries and reporting a breeze.

Return on Investment

  • Early detection of cyber security events and incidents.
  • Processing a large number of network flows on input (which means more than 60K flows per second)
  • Parameterization of detection methods.
  • The possibility to decide on the false-positive rate within the output of each method.

Alternatives Considered

Eset GREYCORTEX MENDEL, Suricata IDS and Snort

Other Software Used

Atlassian Confluence, Nessus, VirusTotal, PortSwigger Burp Suite