Dip Configuration Flashcards
The ____ consists of multiple servers configured as a Collector to store data and Sensors to supply data to the Collector.
DIP
Operators at the Mission Partner site could directly access the DIP while conducting mission operations on-site.
On-Site DIP
The DIP collector resides on the remote site with the Mission Partner.
Remote Operations
The DIP ______ main purpose is to capture MPNET traffic.
Sensor
This program saves raw pcaps to disks.
Arkime (Moloch)
This program analyzes network traffic against specific signature sets.
Suricata
This program can be a signature-based NIDS as well, but gains its power through the use of its scripting language.
Bro (Zeek)
A _____ _______ takes everything it sees on a port or ports you specify, then mirrors it out of another port.
Mirrored Port
- No disconnection needed for implementation
- Requires no hardware
- Can capture all traffic from a switch w/many links
Mirrored Port Pros
- Requires an open port on MPNET switch
- Requires MPNET support and configuration changes to equipment
- May drop packets on a saturated link
Mirrored Port Cons
A _____ is typically a dedicated hardware device providing access data flowing across a network and, ideally, will not affect the speed of the data traversing it.
TAP
- Virtually undetectable
- Does not require Mission Partner Device configuration to install
- Does not require processing power of device to mirror traffic
TAP Pros
- Disconnects the network when hardware is installed
- Only captures traffic sent through one link
- Requires purchase of equipment
TAP Cons
Is a passive, open-source network traffic analyzer.
Bro (Zeek)
A real-time Network Intrusion Detection System (NIDS).
Suricata