Common passive security monitoring tools
In this section, we will discuss some common passive security monitoring tools. I have chosen a single tool for each of the three main disciplines of passive security monitoring, outlined as follows:
- Network security monitoring (NSM)
- IDS
- Event log collection and aggregation
The tool I chose as representative for each category is indicative of its purpose and is chosen because that tool is the most common tool found in the field to perform the category's functions.
NSM
NSM is the art of indexing network traffic artifacts in a way that allows for—among other things—searching, correlating, and the discovery of anomalies, trends, patterns, malicious activities, and code.
By implementing network monitoring tools, we gain an insight into which devices are talking to each other on our network, including what they are talking about, how they talk, and how long for. Knowing this helps us discover...