Chapter_1_Introduction to SilentDefense Flashcards
What are some characteristics of an IT environment?
High density environment
Random changes – hosts coming and going
Hosts running many applications
Throughput and confidentiality are important
What are some characteristics of an OT environment?
Purpose builtHosts running specific application
Longevity and stability are key
Network traffic is fixed – not worried about throuput
Control and integrity are important
What does ICS stand for?
Industrial Control System
Describe an ICS. What does it do?
It is a system which manages or handles an industrial process. For example:a factory which produces cars, an electricity grid, or the transportation system within a city.
What components make up a SilentDefense solution?
A Command Center and one or more sensors.
What are the2 types of sensors used in a live production environment?
Monitoring (Passive) Sensor ICS Patrol (Active) Sensor
Describe a Monitoring Sensor.
Connected to a SPAN or TAP port and monitors traffic to/from ICSPassively inspects trafficSends events and log information to Command Center
Describe an ICS Patrol Sensor:
An optional type of sensor that can be used to query hosts in a controlled way from within the Command Center. This is the only Sensor that is capable of issuing controlled, active requests for information on the network. This will always be done at the request of a SilentDefense user via the Command Center.
What does LAN CP stand for and how does it recognize suspicious traffic?
The LAN Communication Profiler learns a “normal” baseline of traffic, creating a whitelist. Then, after tuning the whitelist, in Detection mode, it sends alerts when traffic is seen which does not match the previously built whitelist.