Passive security monitoring explained
The essence of passive security monitoring lies in the passive part of its name. Truly passive security monitoring does not interact with the environment being monitored. Interactions such as changing files or settings on a host system or sending packets out on a network are avoided, but instead a watch-and-observe approach is taken whereby we monitor files and settings on a host system for changes, or we can observe network traffic to find signs of malicious activity.
Forms of passive security monitoring include the following:
- Network packet sniffing for the detection of malicious activity
- The collection and correlation of event logs to identify malicious behavior/activity
- Host-based security solution agents collecting system statistics to discover malicious activities
We will now discuss the three main methods of passive security monitoring techniques.
Network packet sniffing
Network packet sniffing is the practice...