The anomaly detection engine
Simply put, network behavioral anomalies are detected by the anomaly detection engine. In Figure 8.6, we can see an example of the anomaly detection engine at play. The Port Scan Detected pane depicts all the ports that were scanned by an attacker and the alert calls for immediate attention to the criticality of the incident. A port scan is a network anomaly and is detected by MDIoT:
Figure 8.6 – Example of the anomaly detection engine at play
You can find out more about the alert and the anomaly by viewing the full details of the alert, as shown in Figure 8.7:
Figure 8.7 – Deep dive into the anomaly detection engine
You can find the details about the devices involved, including the Media Access Control (MAC) address, protocols, and vendor.