Preparing for Attacks

Ric Messier · 2017

This chapter describes how to prepare for network attacks and how to acquire and manage NetFlow data. Network devices are capable of generating a fair amount of data, including the flows of traffic passing through them. This can be captured using Cisco's NetFlow protocol. This protocol gives a way of providing data that could be used to troubleshoot a network. This provides a lot of capability for a network forensic investigator. Enabling logging on network devices will help to provide information. While logging systems often store the log data on the device where it is generated, larger enterprises may be more likely to store their logs on centralized logging systems. Security Information and Event Management (SIEM) is considered an intelligence platform that merges some of discussed activites with respect to log management along with an alerting or event management platform.

Read the paper · More papers on PaperTik