Home > -English-, Security > Ground-breaking audit tool for SSH and Windows Remote Desktop Protocol (RDP)

Ground-breaking audit tool for SSH and Windows Remote Desktop Protocol (RDP)

A startup company in China, BMST Co. Ltd., is bringing security managers and auditors a ground-breaking product which can audit SSH and Windows Remote Desktop Protocol (RDP) as a network bridge transparent to the upper layer applications. The product is named Session Auditor. It can record, replay, query, correlate those session data from most of popular protocols used in the daily network and system maintenance and operations, such as SSH, RemoteDesktop(RDP), Telnet, FTP, HTTP, Rlogin, VNC, and even those SQL query in Oracle, Sybase, MS SQL and etc. The most brilliant point is its unprecedented audit capability to the two most popular encrypted protocols, ie. SSH and RDP, making it unique in the competition against common sniffer products as well as forensics tools.

The founders of BMST have put their product at much larger background – the wave of compliance.

In the wake of Enron and WorldCom the role of internal auditors in corporate governance has taken on whole new meaning. Compliance is a long journey that enterprise excutives and IT managers have to take. Although there have been too much in your work breakdown structure task list, however, “Audit” is the right one that you can never overlook for seconds. Audit systems help executives assure everything runing as expected and defined.

Generally speaking, “audit system” for information systems are seperated into two kinds, one is management layer auditing, another one is technical layer auditing. The former is mapped to those auditing tools, particularly based on best practices and standards, such as ISO27001(BS7799), Cobit. But as to the technical layer auditing, there are too many tools and approaches in IT managers’ table. Typically it’s implemented by those log collection and analysis tools in the IDC’s security product category of SIEM(Security Information and Event Management). Those logs are designed to record only the event results, without the details of the activities and operations. In other words, if security managers and auditors want to do in depth investigation and forensics, those logs can’t help any more.

BMST’s Session Auditor can help. It’s an outstanding in-depth investigation and forensics tool. With its huge built-in storage (up to 2T Bytes), SA can record up to 5 months of network traffic in a wire speed fast ethernet (100Mb/s) environment without missing any packet.

Categories: -English-, Security Tags: , , , ,
  1. May 22nd, 2008 at 09:49 | #1

    SA Lite is coming. It’s an all-in-one box with lower price. I believe some SMB or customers with light requirement of audit and forensics must be very interested.

  2. September 3rd, 2007 at 13:08 | #2

    It’s said that the current SA can support script languages to edit/add new audit policy. This script is very powerful. Besides SA, a similar product, named SessionGuard (SG) is around the corner to be released. It will support two models: in-line and offline(ie. work via SPAN port), in the same time.

  3. July 26th, 2007 at 16:04 | #3
  4. August 3rd, 2006 at 03:37 | #4

    ahhhh not a totally software solution. thanks for clearing it up for me

    Chris

  5. August 2nd, 2006 at 13:33 | #5

    it’s composed of two hardware boxes, one is 1U rack-mountable which collects data and send them to the second 2U rack-mountable box which is reponsible for processing data. so it’s impossible to download it. thanks for your interests. please check their website: http://www.bmst.net/en/index.htm

  6. August 2nd, 2006 at 11:54 | #6

    i dont see where to download it. am i missing something?

  7. July 29th, 2006 at 01:34 | #7

    Got it and thanks for the info

  8. July 27th, 2006 at 09:45 | #8

    Hi, Mike, you are welcome.

  9. July 26th, 2006 at 22:27 | #9

    Hi there Richard;
    How are you? It has been a long time since I talked to you.
    I am glad that you guys have completed your work and come up with a fantastic tool for IT Managers.

    How can I get one unit along with complete instructions to play with before I commit myself to you as your distributor in US or at least California ?
    Thanks.

  10. July 26th, 2006 at 09:12 | #10

    According to my knowledge, it’s internal maintenance and operation oriented, so as the design, it does’t support Skype at the beginning. Additionally, to decrypt Skype is not practical at this moment, even we have had the news that a team from China has succeeded in breaking the Skype protocol. ;)

  11. July 24th, 2006 at 15:42 | #11

    sounds a good tool for IT managers, especially for those who have security concerns about their business. The major concerns of IT manager who are looking for auditor tools is that whether or not the tool can capture, record, replay all the traffic they want.

    Just one question, can this application decrypt the point to point encrypted data traffic such as Skype?

  1. November 14th, 2009 at 08:32 | #1
*