Passive network audit framework
J Javier Santillan Arenas · 2014
“Passive Network Audit” technology includes network discovery and monitoring techniques in which network packets are captured, processed and analyzed in order to gather information about the network. It relies on passive analysis of network traffic activities, meaning that no single active interaction takes place between auditor and network environment. The goal of passive network audit is to assess the security level of the network environment, based on predefined baselines (e.g policies, rules). By using different detection techniques such as protocol behaviour analysis, network enumeration, signature-based Intrusion Detection Systems (IDS), Network Flow Analysis (NFA) and Deep Packet Inspection (DPI), it is possible to identify network threats taking into account network elements, patterns and known vulnerabilities. This research aims to identify the gap between Network Security Monitoring (NSM), Security Information and Event Management (SIEM) and Passive Network Audit (PNA) by analyzing some taxonomies and existing frameworks. Findings of this background study are taken into consideration to define a security framework which is intended to take features of different technologies in order to provide a very flexible, automated and reliable assessment framework that can be implemented as passive audit technology. Hence, this framework aims to provide complementary features to SIEM and NSM approaches in order to get a better context of security events. Furthermore, this thesis defines the prototype that provides the capabilities of an automated passive network audit engine. It was developed as internal project of Fox-IT. Passive Network Audit Framework iii