Network Traffic Analysis
Alfred Basta, Nadine Basta, Waqar Anwar, Mohammad Ilyas Essar · 2024
Network taps and mirrored switch ports allow the copying of select production traffic to isolated visibility subnets for inspection without impacting performance or availability. Connecting network event details with disparate identity management systems attributes precise attribution. Unifying internal and external intelligence provides network perimeter defenses in real-world contexts to block emerging attacks while avoiding over-filtering legitimate activities. Continuously updated threat data also focuses monitoring on high-risk services demanding scrutiny. The protocol analyzer model permitted messaging sequences and data transmission norms to expose anomalies indicative of exploitation or misuse. Strategically positioned network sensors analyze traffic payloads and behaviors to detect malicious activity and threats. Network-based Intrusion Detection Systems identify and report issues, while Network-based Intrusion Prevention Systems can additionally mitigate them through active prevention. Examining impacts requires determining assets and data compromised: account takeovers enabled, duration of exposure, and subsequent damages.