Network Monitoring Flashcards
the de facto protocol for network management on TCP/IP networks
Simple Network Management Protocol (SNMP)
part of an SNMP system that requests and process information from managed devices; uses UDP port 162 or, with TLS, TCP port 10162.
SNMP manager
the specialized software run by the SNMP manager
network management station
the specialized software run by managed devices in an SNMP system; uses UDP port 161 or, with TLS, TCP port 10161
agent
a protocol that can be adapted to accomodate various needs, like SNMP
extensible protocol
used by SNMP to categorize the information that can be queried; inform SNMP monitors what can be monitored on a specific device
management information base (MIB)
the eight core functions of an SNMP system
protocol data unit (PDU)
function sent by an SNMP manager when it wants to query an agent
Get
function sent by an SNMP manager to make changes to variables
Set
function sent by an agent containing the requested information from a Get request
Response
function used by an agent to solicit information from an NMS or send information to the NMS without first being queried
Trap
SNMP utility that tells the SNMP manager to perform a series of Get commands
snmpwalk
SNMP capability that sends alert notifications to techs, such as through text messages or email
event management
program that queries a network interface and stores packets in a capture file on a computer, router, or dedicated piece of hardware; used where there is a suspicion of malicious network access/probing; need to collect as much data as possible, usually set in promiscuous mode or via a mirrored port on a switch
packet sniffer/sniffer
Cisco tool found in their routers and switches that tracks traffic flowing between specific source and destination devices
Netflow
tool that tracks the bandwidth and utilization of one or more interfaces, such as a physical port or ports, on one or more devices
interface monitor
a tool that keeps track of the performance of a certain aspect of a system over time; requires detailed understanding of the low-level aspects of the system, so it’s usually tied to an operating system or application
performance monitor
the particular aspect that is tracked by a performance monitor
counter (Perf Mon); facility (syslog)
computers in a network that are receiving the most data
top listener
network monitoring approach that is a mashup of SEM and SIM; typically only used by large enterprises; can be self-implemented or administered by a vendor
security information and event management (SIEM)
process of monitor security event in real-time, often through edge devices, and saving the events to a location to be analyzed; also collects and centralizes disparately located event logs
security event management (SEM)
process of SIEM where the saved log files are analyzed, either through automated or human interpreters
security information management (SIM)
the process of checking for changes in various aspects of a file
file integrity monitoring
vendor who is under contract to administer an SIEM system
managed security service provider (MSSP)