SECFND 13: Security Data Collection Flashcards
Transaction Data
Operations that occur during network sessions
Epoch time
of seconds since 1/1/70
TCP_Hit (Proxy)
Cached in proxy
HTTP 200 Series
Successful
HTTP 300 Series
Redirected
HTTP 400 Series
Client side errors (403 forbidden, 401 Unauthorized)
HTTP 400 Series
Server side errors
HTTP Get
Retrieval and simple searches
HTTP Post
Submit Data-query
HTTP Put
Upload files
HTTP Head
Retrieve Metadata
HTTP Delete
Remove resource
HTTP Trace
Application layer trace of route
HTTP Option
Request available methods
HTTP Connect
Tunnel SSL Connection
HTTP Propfind
Retrieve properties of an object
IPFIX
Latest version of netflow
A flow
unidirectional series of packets between a source and a destination. 5 tuple is constant in a flow
Flow stitching
Combines unidirectional flow records into once record
NAT Stitching
Combine internal and external NAT info into one record
Netflow provides…
An audit trail