day 1 Flashcards
network analysis tools and techniques
security specialists need continuous intelligence about the behavior of workstations, servers, network devices, and applications to efficiently monitor and enhance the security posture and operations of their network
network baselining
a baseline is a statistical profile of a certain performance metric-network device or application utilization, response time, or volume
historical baselines reflect traditional (normal) network operations. normal traffic includes:
- traffic type
- volume of each traffic type
- direction, flow of each traffic type
detecting security breaches
in detecting security breaches, the most beneficial data sources will be those that give detailed network utilization and application volume of the network and its applications.
baselining methods and techniques
- top to bottom network monitoring
- application monitoring
- detailed packet analysis
- continuous traffic capture
- threshold alarms
- packet analysis methodology
top to bottom monitoring
a solution must provide the capability to see the network from a high-level holistic (summary) perspective to pinpoint trouble spots quickly
most used to least used
application monitoring
types of application monitoring include: well-known web-based complex custom unknown
detailed packect analysis
detailed packet-level analysis allows the security specialist to identify the specific code used in an attack
continuous traffic capture
solutions must supply a means to continuously capture and store a complete packet by packet network traffic audit trail for several days
threshold alarms
threshold alarms can be set based upon the network baseline previously developed. These alarms alert the security specialist when a specific metric has been exceeded.
packet analysis methodology
plan deploy capture analyze refine
common network traffic
there are two basic categories of protocols:
binary-transmit commands as binary info
textual-transmit commands in a text format….HTTP, HTTPS, SMTP, POP, IMAP
study protocols on page
do it!
ethernet header
makes up the first 14 bytes of the ethernet frame (662)
next protocol types
0800 IPv4
0806 ARP
86dd IPv6
values less than 1500 (or ones not listed above!) indicate a length field and is not a protocol