BIG Traffic Replication & Aggregation System

Uses bypass mirroring and optical splitting to replicate, aggregate and centrally analyze full traffic volumes, providing the data foundation for upstream detection and forensics.

OVERVIEW

Product Overview

BIG Traffic Replication & Aggregation System is an Ethernet traffic replication and aggregation appliance designed for big data monitoring, traffic analysis and cybersecurity surveillance. It connects to the network non-intrusively through bypass mirroring and optical splitting to collect north-south and east-west traffic in full volume with high throughput and low packet loss, aggregating dispersed network traffic into a unified, analyzable and traceable data foundation.

The system delivers deep multi-protocol parsing and sensitive field masking, and uses hot/cold tiered storage to support long-cycle retrieval and forensics. A single traffic copy can be delivered on demand to multiple security systems — sandbox, situational awareness, IDS and more — achieving collect once, consume everywhere. Bypass deployment does not affect business operations, and full retention meets forensic and compliance audit requirements.

CORE FEATURES

Core Features

High throughput and low packet loss — one traffic copy empowering every security system on the network

01

Full-Volume Bypass Collection

Non-intrusive collection via mirroring / optical splitting, covering north-south and east-west traffic, with flexible switching between operating modes and pure-chip processing for high speed and reliability.

02

Protocol Parsing & Masking

Deep multi-protocol parsing and metadata extraction, with sensitive fields masked before secure delivery, balancing analytical capability with data compliance.

03

Full-Traffic Storage & Retrieval

Hot/cold tiered storage architecture supporting long-cycle traffic retention and retrieval, with any time window replayable on demand to meet forensic requirements.

04

On-Demand Multi-Consumer Delivery

Traffic aggregation, deduplication and intelligent distribution, delivering one traffic copy to sandbox, situational awareness, IDS and other systems for parallel analysis.

AGGREGATION ARCHITECTURE

Platform Architecture

A four-stage processing chain that turns dispersed traffic into an analyzable, traceable data foundation

1

Collection Probes

Bypass collection via mirroring / optical splitting, with no business intrusion

2

Aggregation & Distribution

Traffic aggregation, deduplication and intelligent distribution

3

Parsing & Masking

Protocol parsing, metadata extraction and sensitive field masking

4

Storage & Delivery

Hot/cold tiered storage with on-demand delivery to multiple consumers

Closed-loop linkage: one traffic copy delivered to multiple consumers, continuously feeding sandbox detonation, situational awareness and IDS.
SCENARIOS & VALUE

Scenarios & Value

Full-Traffic Audit & Retrieval

Rapidly reconstructing traffic and the full attack process
  • Long-cycle traffic retention
  • Complete attack process reconstruction
  • Any time window replayed on demand

Attack Forensics

Evidence chains for analysis and attribution
  • Complete, traceable evidence chain
  • Supports attribution and compliance
  • Evidence chain meets forensic compliance requirements

Feeding New-Threat Detection

Continuous supply to sandbox and situational analysis
  • Collect once, consume everywhere
  • Continuous supply to analytics systems
  • Multi-engine parallel analysis for efficiency
Full Retention
Traffic traceable at any time
Complete Evidence
Forensic chains you can trust
Collect Once
Shared data supply across systems
Retention Compliance
Audit-ready by design