SECOPS 2: NSM Tools and Data Flashcards
Session data
Summary data for network connections. Who talked to whom and when. Like a phone bill.
5 Tuple with timestamps
Full Packet Capture format
PCAP
Full content data
aka full packet capture
Transaction data
Details associated with requests and responses.
Example: Client GET request and server response
Alert data
Typically from IPS. Network traffic matches conditions to generate alert.
Statistical data
Statistics derived from NSM data
Statistical data over time produces…
baselines
Baselines define
what is normal
Anomalies
Deviations from normal
Metadata
Data about data.
Bro produces … but can produce…
Session data, but can produce almost any data type (transaction, extracted, alert, etc.)