Threat Map

OUR PRODUCTS, BEFORE YOU NEED IT.

TM

Geolocalized Threat Map

The Threat Map module has the purpose of displaying the map of attacks worldwide (type WORLD), or attacks carried out on the local infrastructure (type LOCAL). As a detail view it shows the most frequent types of attacks and the countries that send the most attacks.

Real-time attack map

The module can apply a block on the perimeter firewall or a BlackHole route on border routers to geolocate an attack. TIG investigations can also provide customised protection for the organisation's infrastructure.

01

World attack views (WORLD)

The module displays the data of the attackers, geolocating them on the map. The log inputs from the customer's IPS-IDS-SIEM FW further feed the data displayed on the map. In addition, our TIG (Tecninf Intelligence Group) collects data worldwide and further integrates the information contained in the map.

02

Attack arcs

The module reads a file in .csv format (attacksList.csv) which is updated at regular intervals. For each record contained in the attacks file, the map also displays an arc connecting the two geographic coordinates.

03

Local attack views (LOCAL)

By activating this mode, the Threat Map displays the attacks carried out on the local infrastructure. Data containing the IP addresses that generated the attacks are sent to TCP and UDP type servers, which allows the acquisition of attacks brought to your framework.