NBA stands for Network Behavior Analysis. More specifically, NBA for z/OS offers a unified flow analysis system for
applications and users by analyzing traffic on a z/OS platform and correlating and consolidating complex transaction
components as they travel through CICS, DB2 or IMS.
NBA for z/OS can be downloaded from the ServicePilot website. It requires a login and password which you can request
here.
This will provide you with access to the FREE version of NBA for z/OS. To request a free, 30-day evaluation of the latest
FULL version of NBA for z/OS, please contact your sales representative here.
NBA for z/OS Free Edition traces all the IP traffic flowing through the IP dataspace. This traffic can be browsed,
either as the trace is running, or once it has been archived.
NBA for z/OS FULL Edition includes tracing (FREE edition) as well as monitoring of all IP stack activity including
TCP, UDP, ICMP, OSPF, Enterprise Extender and XOT.
It also permits the monitoring of resources: Host presence; port activity; router activity; connection and interface states;
and traffic level.
NBA for z/OS can be downloaded and installed on your z/OS system in as little as 30 minutes.
Configuration consists of security definitions, defining NBA datasets, and modifying the JCL in the started task.
IP resources are automatically discovered on initialization of NBA for z/OS and you will have immediate access via a browser
interface.
Trace data can be viewed as the trace is running. Optionally, trace data from 1 minute to up to the previous 15 minutes
can be displayed. A user-friendly interface displays a meaningful presentation of the trace.
NBA for z/OS is based on a real-time technology that allows its collector interface to provide availability
and performance data for network components on the mainframe. NBA for z/OS uses non-invasive probes to browse
the data as it traverses the IP stack as well as at the datagram level. Optionally, ping is used for remote application
availability monitoring.
Yes, traces can be saved in text or sniffer formats for import into products such as WireShark.
NBA for z/OS analyzes mainframe traffic, correlates and consolidates complex transaction and delivers the appropriate detailed statistics using more than 40 indicators:
- Availability %
- Traffic - In/Out Bytes, In/Out Packets, Packet Size Distribution
- Bandwidth - In/Out bps, In/Out pps
- Response Time – Host and Network, Response time distribution
- IP – Fragmented packets
- TCP - Active/Started/Stopped Connections, Anomalies (Duplicate ACK, RST, Retransmits, Window < 1500 Bytes)
NBA for z/OS is accessed via a Web browser using JAVA.
Microsoft Silverlight is required in order to access the behavior analysis feature of NBA for z/OS.
ServicePilot NBA for z/OS Behavior Analysis offers a unified flow analysis system for applications and users.
It correlates and consolidates complex transaction components (CICS, DB2 or IMS) and delivers detailed statistics on
transaction flows. Thanks to its user identity tracking, ServicePilot NBA for z/OS correlates usernames with host IP
addresses related to transactions. It identifies the “who” behind the “what”, pinpoints the source of mainframe activities
with specific end-users and automatically determines who is responsible for, as well as who is affected by, an unexpected event.
When applied to IP Networks, the Behavior Analysis feature of ServicePilot NBA for z/OS helps you identify who
is consuming network resources. Filters can be customized and applied for accurate analysis. Analysis can be done
on Last 24 Hours statistics or on previous days’ or weeks’ statistics.
No servers or agents are required to use NBA for z/OS.
NBA for z/OS is compatible with all SAF products (RACF, TOP SECRET, ACF2).
NBA for z/OS is written in Assembler language and uses passive probes to browse and analyze data as it traverses
the IP stack. Therefore only a small amount of CPU cycles are required by NBA for z/OS.
Yes, NBA for z/OS monitors HPR and EE providing the following:
- List of Switched Pus
- For each Switched PU
- Status (CONNECTABLE, INACTIVE...)
- Nb RTPs (Last minute value)
- List of RTPs for a Switched PU
- For each RTP
- Nb sessions attached (Last minute value)
- Sent bytes (Real-time)
- Received bytes (Real-time)
- Sent Network Layer Packets (Real-time)
- Received Network Layer Packets (Real-time)
- List of Sessions for an RTP
- For each « CP Name » as well as information about the topology of an APPN network.
ServicePilot NBA for z/OS also collects IP data from distant HPR nodes.
It is then possible to know the traffic evolution for each distant node, as well as its prioritized distribution
(Network, High, Medium, Low, LLC commands).
Yes, ServicePilot NBA for z/OS permits the generation of on demand and/or batch reports on applicative resource or user behaviors. The batch reports are dependent on the duration of information retention, which may be set by the administrator. These reports can be exported into a csv file or pdf format.
ServicePilot NBA for z/OS can detect suspicious connections, analyze network traffic and understand their relevance with a defined set of rules. It protects the corporate network against malicious traffic and generates real-time alarms. Using DPI (Deep Packet Inspection) technology, ServicePilot NBA for z/OS looks for a pattern within a packet from a defined point and triggers a response according to the search result.
ServicePilot NBA for z/OS can generate alerts because of Deep Packet Inspection rules.
These rules allow the detection of: bad or malformed traffic, bad ICMP messages, and application attacks (FTP, Telnet, HTTP...).
A default set of rules is provided but you can define your own detection rules according to your environment.
ServicePilot NBA for z/OS sets behavior rules adapted to the enterprise by linking one or several actions with conditions applied on the application or network resource availability and/or performance.
When the conditions are met (i.e., bad application response time), ServicePilot NBA for z/OS notifies operators by generating real-time alarms. These alerts are displayed via a Web browser or a 3270 interface and are automatically archived in SMF format. Operators will be able to see meaningful changes in behavior and take action before these changes affect or disrupt users.
Yes, by defining alarms based on network & system availability and performance metrics, notification can be formatted to be sent as an SMTP trap, a syslog message, or an email or pager.
Yes, many parameters can be modified while the product is running, then they can be updated by reloading via the Web interface.
NBA for z/OS can be used by individuals involved in installing, configuring, operating, and securing z/OS networks, network and security professionals, including I/T, I/S managers, systems planners, analysts, integrators, and administrators, technicians responsible for diagnostic including network operations personnel.
Yes. However, NBA for z/OS is so easy to configure and navigate that most users do not require additional assistance. Our customers have reported that they were able to very quickly become familiar with NBA for z/OS and found the GUI interface to be very intuitive and easy to use.