BrightCloud Vector
Background
The dynamic and complex nature of today's Internet provides rich resources but also generates undesirable traffic. Inbound probing from suspicious sources consumes the processing power of edge of network devices. Outbound communication with potentially malicious sources can result in internal infections from malware, Botnets, and more.
Rapidly changing IP addresses from threat sources creates demand for dynamic visibility into network traffic and the proactive protection to block attacks before they occur. Edge of network devices must protect against continually evolving threats from spam, exploits, Botnets, web attacks, scanners, and other sources across the Internet.
Overview
BrightCloud Vector identifies threats across multiple sources and publishes a dynamic data set of high-risk IP addresses. Vector improves visibility into malicious inbound and outbound network traffic to enable flexible policy reporting and implementation. Vector's dynamic data set refreshes continuously, capturing the latest IP threats while removing IPs that are no longer a security risk. Vector integrates with edge of network devices and can free as much as 30 – 40 % of the work load off devices.
How BrightCloud Vector Works
Vector leverages the BrightCloud Threat Operation Center's (TOC) global threat sensor network, which monitors the Internet around the clock for malicious activity. The TOC utilizes BrightCloud's Internet resource and reputation data to identify high-risk IP addresses. The TOC detects threats across multiple sources, such as:
- Spam senders
- Botnets
- DDoS attack sources
- Click fraud
- Windows Exploits
- SMB
- RPC
- SQL server
- Malware
- Web attacks
- SQL injection attacks
- Cross-site scripting
- Application infrastructure attacks
- Dictionary attacks
- Trojans, worms
- Scanners
- Vulnerability probes
Current and future reputation scores for IP addresses are calculated to improve visibility and forecast future risk levels. IPs with untrustworthy reputation scores are published by Vector.
The BrightCloud Service delivers updates to Vector within minutes. The latest IP threats are continuously added to Vector's dynamic data set. Unlike traditional IP blacklists, IP addresses that have been previously published in Vector's data set are removed when the reputation score improves above the malicious threshold. Vector keeps pace with a dynamic threat landscape and facilitates proactive protection.
The Vector Software Development Kit (SDK)
The Vector Software Development Kit (Vector SDK) is targeted at C software developers and demonstrates how to integrate Vector into an OEM partner's solution. Registered users can obtain the Vector SDK by visiting http://www.brightcloud.com. To become a registered user please contact BrightCloud Sales at sales@brightcloud.com.




