Narus
Narus was a U.S. software and network-analytics company known for real-time analysis of carrier-grade Internet traffic and cybersecurity applications.
Last updated August 31, 2026
Overview
Narus was an American software company that developed large-scale network-traffic monitoring and analytics systems for telecommunications carriers, government customers, and other organizations. Founded in 1997 by Ori Cohen and Stas Khirman in Israel, the company initially focused on the operational and commercial problems created by the rapid growth of Internet Protocol networks. Its early systems captured and analyzed network traffic in real time, helping carriers understand usage patterns, support billing, and identify what Narus described as revenue leakage—unbilled or incorrectly billed network use. The company’s technology operated at the infrastructure level rather than as a conventional consumer-facing software product. Narus systems could process very large volumes of IP traffic and extract information about protocols, applications, sessions, and usage. This made the technology relevant to telecommunications operators that needed visibility into increasingly complex networks. It also positioned Narus in the broader enterprise and cybersecurity-analytics market, where real-time traffic inspection could be used for network management, threat detection, policy enforcement, and investigations. After the September 11, 2001 attacks, Narus expanded the semantic and monitoring capabilities of its products. The company’s tools became associated not only with carrier billing and network operations but also with deep packet inspection, content filtering, and surveillance-oriented analysis. Such capabilities allowed network administrators to inspect, track, classify, and target traffic as it passed through routers and other network infrastructure. Narus equipment was reported to have been used by Telecom Egypt, while Pakistan’s and Saudi Arabia’s national telecommunications authorities were identified as customers in the company’s international market. Narus also became publicly associated with the debate over government access to telecommunications networks. Whistleblower accounts from former AT&T technician Mark Klein and former National Security Agency official Thomas Drake linked Narus hardware and software to an AT&T facility used for intercept-related activity. The allegations were discussed in reporting and documentary coverage concerning Room 641A and the broader U.S. telecommunications-surveillance controversy. The association made Narus a prominent example in discussions about the dual-use nature of carrier-grade monitoring technology: the same systems that can support billing, fraud prevention, and security can also facilitate extensive inspection of communications traffic when deployed under governmental or operator authority. In 2010, Narus became a subsidiary of Boeing and was based in Sunnyvale, California. The acquisition placed the company within Boeing’s broader security and technology portfolio. In 2015, Narus was sold to Symantec. Publicly available reference material does not establish a complete standalone operating history after that transaction, including whether the Narus brand continued independently, was integrated into Symantec offerings, or was later discontinued. Narus should therefore be understood primarily as a former specialist vendor of carrier-grade network intelligence, deep packet inspection, and cybersecurity analytics rather than as a currently verifiable independent consumer brand.
History
Narus was established in 1997 by Ori Cohen and Stas Khirman in Israel. Both founders had backgrounds connected with VDONet, where Cohen had served as vice president of business and technology development. Narus entered the market during the rapid expansion of Internet Protocol networking, when telecommunications carriers were moving from traditional voice infrastructure toward data-heavy networks that were more difficult to measure, manage, and bill. Its initial business centered on carrier-grade tools for collecting and analyzing IP traffic in real time. The systems were intended to give operators detailed visibility into network use and to help identify revenue leakage, meaning network activity that was not properly measured or charged. This commercial and operational focus placed Narus within the telecommunications-infrastructure software sector rather than the consumer Internet market. The company’s technology was designed for high-volume environments where traffic had to be classified and analyzed as it moved through network equipment. Following the September 11, 2001 attacks, Narus broadened its technology with what reference material describes as semantic monitoring capabilities. These functions supported more detailed interpretation of traffic and enabled use cases such as deep packet inspection, content filtering, policy enforcement, and surveillance analysis. Narus supplied deep packet inspection equipment to Telecom Egypt, and national telecommunications authorities in Pakistan and Saudi Arabia were identified as customers. The international deployments illustrated both the commercial reach of the technology and its sensitivity, because traffic-inspection systems can be used for network management and cybersecurity as well as for censorship or state surveillance depending on the deployment and governing authority. In 2004, Narus appointed William Crowell, a former deputy director of the National Security Agency, as a director. His involvement reflected the company’s increasing relevance to the government-security and communications-monitoring sectors. Narus later became associated with the U.S. debate over telecommunications interception. Former AT&T technician Mark Klein described a secure facility at an AT&T site in San Francisco, commonly known as Room 641A, where he alleged that equipment including a Narus STA 6400 was used to copy or analyze communications traffic. Former NSA official Thomas Drake also linked Narus technology to AT&T wiretapping rooms. These claims became part of wider public discussion involving the NSA, the Communications Assistance for Law Enforcement Act, and the Electronic Frontier Foundation’s litigation against AT&T. The allegations were also featured in documentary coverage. The available reference material establishes the controversy and the reported association, but it does not independently establish every operational detail alleged by the whistleblowers. In 2010, Boeing acquired Narus, making it a subsidiary headquartered in Sunnyvale, California. The transaction brought Narus into Boeing’s security and technology activities. In 2015, Boeing sold the company to Symantec. The available reference material does not provide a detailed account of Narus’s post-acquisition product road map, management, or legal entity status. It consequently remains unclear whether Narus continued as a separately marketed brand, was integrated into Symantec’s enterprise-security portfolio, or was later wound down. Historically, Narus is best characterized as a specialist provider of large-scale network-traffic analytics and inspection technology whose products occupied the boundary between telecommunications operations, cybersecurity, lawful interception, and state surveillance.
- 2015Sale to Symantec
Boeing sold Narus to Symantec.
- 2010Boeing acquisition
Narus became a subsidiary of Boeing and was based in Sunnyvale, California.
- 2004William Crowell joins as a director
Former NSA deputy director William Crowell became a Narus director.
- 2001Network monitoring expands toward semantic analysis
After the September 11 attacks, Narus added more advanced semantic monitoring capabilities to its network-analysis technology.
- 1997Narus is founded
Ori Cohen and Stas Khirman founded Narus in Israel to develop large-scale tools for analyzing IP network traffic.
Products and positioning
Narus positioned its technology as high-scale, real-time network intelligence for telecommunications operators, cybersecurity users, and government-related customers. Its core value proposition combined traffic visibility, operational analytics, billing assurance, policy enforcement, and security or surveillance analysis.
Narus network-traffic analytics platformsNetwork analytics software1997
Narus developed systems that captured and analyzed computer-network traffic in real time. The platforms were designed for carrier-scale environments and could support traffic classification, usage analysis, billing assurance, network operations, and cybersecurity investigations. Their commercial purpose included helping telecommunications operators identify unbilled or incorrectly billed usage, while later capabilities enabled more detailed semantic interpretation of network activity.
Narus Semantic Traffic Analyzer (STA)Deep packet inspection and traffic monitoring
The Narus Semantic Traffic Analyzer was associated with the company’s ability to inspect and interpret high-volume IP traffic. Reference material identifies an STA 6400 in accounts concerning an AT&T facility connected to surveillance allegations. More generally, Narus STA technology was used for deep packet inspection, content filtering, traffic tracking, and targeting of network or mobile communications as they passed through telecommunications infrastructure.
Carrier revenue-leakage analysis toolsTelecommunications billing assurance1997
Narus’s early products helped carriers analyze IP-network usage for billing and revenue assurance. These tools were intended to identify traffic or services that were not properly recorded or charged, addressing a major operational problem as telecommunications networks carried increasing volumes of packet-based data.
Deep packet inspection and content-filtering equipmentNetwork security equipment
Narus supplied equipment capable of inspecting, classifying, tracking, and filtering content in Internet and mobile-phone traffic. These capabilities could be used by network managers for policy control and security, but they also made the products relevant to government surveillance and censorship applications. Telecom Egypt is identified as a customer in the reference material.
Flagship businesses
- Narus Semantic Traffic Analyzer (STA) systems
- Carrier-grade IP traffic analysis and monitoring platforms
- NarusInsight
- Narus STA 6400
Brand decisions
- 2015Boeing sells Narus to SymantecM&A
Narus was operating as a Boeing subsidiary after the 2010 acquisition.
What changed. Boeing sold Narus to Symantec.
Aftermath. Symantec became Narus’s parent company. The available reference material does not establish whether the Narus name and products continued as a distinct business after the sale.
- 2010Boeing acquires NarusM&A
Narus had developed carrier-scale network analytics and security-monitoring technology with applications in telecommunications and government-related markets.
What changed. Boeing acquired Narus and operated it as a subsidiary based in Sunnyvale, California.
Aftermath. Narus became part of Boeing’s security and technology activities. The available reference material does not provide transaction value or detailed integration results.
- 2001Expansion from billing analytics into semantic monitoringStrategy
Narus initially concentrated on carrier-grade IP traffic analysis for billing and revenue assurance. After the September 11 attacks, the company expanded its capabilities toward more detailed semantic monitoring of network traffic.
What changed. The company added functionality supporting deep packet inspection, content filtering, traffic classification, and surveillance-oriented analysis.
Aftermath. The shift broadened Narus’s relevance to cybersecurity and government customers but also contributed to public controversy over the use of its technology in telecommunications interception.
Leadership
| Name | Title | Tenure |
|---|---|---|
| William Crowell | Directorformer | 2004– |
| Ori Cohen | Co-founder; previously associated with Narus leadershipformer | 1997– |
| Ori Cohen | Co-founderformer | 1997– |
| Stas Khirman | Co-founder; previously associated with Narus leadershipformer | 1997– |
| Stas Khirman | Co-founderformer | 1997– |
Controversies
- 2006AT&T wiretapping and Room 641A controversyControversy
Whistleblowers Mark Klein and Thomas Drake linked Narus equipment and software to AT&T facilities involved in allegations that the NSA obtained or analyzed large volumes of customer Internet and voice-over-IP communications. The claims became associated with Room 641A, Electronic Frontier Foundation litigation against AT&T, and wider controversy over telecommunications surveillance. The public record described an alleged use of Narus technology; it does not by itself resolve every factual or legal issue surrounding the allegations.
Recent events
- 2015Narus is sold to Symantec
Boeing sold Narus to Symantec, ending Narus’s period as a Boeing subsidiary. Public reference material does not document the subsequent standalone status of the Narus brand in detail.
M&A - 2015Symantec acquires Narus from Boeing
Boeing sold Narus to Symantec, ending Narus’s period as a Boeing subsidiary.
M&A - 2010Narus becomes a Boeing subsidiary
Narus was acquired by Boeing and operated as a subsidiary focused on network analytics and security technology.
M&A - 2010Boeing makes Narus a subsidiary
Narus became a subsidiary of Boeing and operated from Sunnyvale, California.
M&A - Narus deep-packet-inspection systems used by telecommunications authorities
Reference material identifies Telecom Egypt and the telecommunications authorities of Pakistan and Saudi Arabia among Narus’s customers for network-inspection or related technologies.
Other
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/narus · Editorial policy · How profiles are compiled