NETWORK TRAFFIC MONITORING AND ANALYSIS
DR. MOHAMMAD SHOAB
CONTENTS
INTRODUCTION
WHAT IS NETWORK MONITORING?
WHAT IS NETWORK TRAFFIC ANALYSIS?
NEED OF NETWORK TRAFFIC ANALYSIS
-Abnormal packets
-Network slow performance
1. congestion
2. Retransmission
-Unexpected traffic
-Broken applications
-Load balancer issues
-Collecting evidence
-Incident Handling
-Tracing attacks
-Linking infected hosts
-Determining patient zero
HOW TO SOLVE NETWORK TRAFFIC?
FEATURES OF NETWORK TRAFFIC ANALYSIS
Whether the network communications in question are traditional TCP/IP style packets, virtual network traffic crossing from a vSwitch, traffic from and within cloud workloads, API calls to SaaS applications, or serverless computing instances, NTA tools have the ability to monitor and analyze a broad variety of communications in real-time.
With over 70 percent of web traffic encrypted, organizations need an accessible method for decrypting their network traffic without disrupting data privacy implications. NTA solutions deliver on this challenge by enabling security professionals to uncover network threats by analyzing the full payload without actually peeking into it.
NTA products offer the ability to track and profile all entities on a network, including the devices, users, applications, destinations, and more. Machine learning and analytics then attribute the behaviors and relationships to the named entities, providing infinitely more value to organizations than a static list of IP addresses.
Because NTA tools attribute behaviors to entities, ample context is available for detection and response workflows. This means security professionals no longer need to sift through multiple data sources such as DHCP and DNS logs, configuration management databases and directory service infrastructure in an attempt to gain comprehensive visibility. Instead, they can quickly detect anomalies, decisively track them down, determine the root cause and react accordingly.
To keep up with ever-changing modern IT environments, NTA solutions track behaviors that are unique to an entity or a small number of entities in comparison to the bulk of entities in an environment. The underlying data is available immediately and NTA machine learning baselines evolve in real-time as behaviors change. Also, with entity tracking capabilities, NTA baselines are even more comprehensive as they can understand the source and destination entities, in addition to traffic patterns. For instance, what might be normal for a workstation is not normal for a server or IP phone or camera.
NETWORK ANALYZERS
IMPORTANCE OF NETWORK TRAFFIC ANALYSIS
USECASES FOR ANALYZING NETWORK TRAFFIC
�WHAT TO LOOK FOR IN A NETWORK TRAFFIC ANALYSIS�
NETWORK PROTOCOLS
ARCHITECTURE DIAGRAM
CONCLUSION
FUTURE SCOPE
THANK YOU