Diverse ways of traffic mirroring for OT monitoring
Network sensors, which are a significant part of the MDIoT architecture, receive data or traffic from the following:
- SPAN ports
- The network terminal access point (TAP)
In Figure 5.4, we can see that the OT devices send traffic for analysis through the managed switch with port mirroring:
Figure 5.4 – Example of the network used in an OT environment
We will now learn about different methods used for traffic mirroring in an OT environment to enable monitoring with MDIoT.
To focus on specific and relevant network traffic for traffic analysis, you need to connect MDIoT to a network mirroring port on a switch or a TAP that only covers industrial ICS and SCADA traffic.
SPAN
Port mirroring, commonly known as Switched Port Analyzer (SPAN), is a method of monitoring network traffic. When port mirroring is enabled, the switch sends a copy of all the network packets visible on a single...