9
Chapter 9: Forensic Analysis
Examining your network traffic with forensic analysis
Forensic Analysis is a powerful tool for scanning high-volume packet captures
for intrusion signatures and other traffic patterns that can be specified using the
familiar Snort rule syntax.
Network forensics is the idea of being able to resolve network problems through
captured network traffic. Previous methods of network forensics required you
to be able to recreate the problem. Using the Observer GigaStor you do not
have to recreate the problem — you already have the captured packets. Instead
of reacting to a problem, you can use network forensics to proactively solve
problems.
You might need network forensics because of company policy or because of
governmentally-mandated compliance. You can enforce your “acceptable use”
policies, fight industrial espionage, and assist with government regulations like
Sarbanes Oxley or HIPPA requirements. Using network forensics you can provide
pre-intrusion tracking and identification while delivering a paper trail after any
intrusion. Or you can perform network troubleshooting using root-cause analysis
and identify network problems that have been around awhile.
Snort is an open source network intrusion detection system (NIDS). Snort’s rule
definition language is the standard way to specify packet filters aimed at sensing
intrusion attempts. You can obtain the rules from
.
Snort rules imported into Observer Analyzer operate much like Observer’s expert
conditions, telling Observer how to examine each packet to determine whether
it matches specified criteria, triggering an alert when the criteria is met. They
differ from expert conditions in that they only operate post-capture, and the
rules themselves are text files imported into Observer.
Содержание Apex Enterprise G3-APEX-ENT-32T
Страница 1: ...Observer GigaStor 17 2 0 0 User Guide 23 Feb 2018 ...
Страница 48: ...G3 GS 8P 288T 48 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 29 G3 GS 8P 288T Front ...
Страница 78: ...GS 2P40 576T 78 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 51 GS 2P40 576T Front ...
Страница 85: ...GS 2P40 288T Chapter 1 Appliance installation 85 Figure 55 GS 2P40 288T Front ...
Страница 86: ...GS 2P40 288T 86 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 56 GS 2P40 288T Rear System ...
Страница 90: ...GS 2P40 288T 90 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 57 GS 2P40 288T Rear ...
Страница 93: ...GS 8P 576T Chapter 1 Appliance installation 93 Figure 59 GS 8P 576T Front ...
Страница 100: ...GS 8P 288T 100 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 101: ...GS 8P 288T Chapter 1 Appliance installation 101 ...
Страница 102: ...GS 8P 288T 102 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 103: ...GS 8P 288T Chapter 1 Appliance installation 103 ...
Страница 104: ...GS 8P 288T 104 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 105: ...GS 8P 288T Chapter 1 Appliance installation 105 ...
Страница 106: ...GS 8P 288T 106 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 107: ...GS 8P 288T Chapter 1 Appliance installation 107 ...
Страница 108: ...GS 8P 288T 108 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 109: ...GS 8P 288T Chapter 1 Appliance installation 109 ...
Страница 110: ...GS 8P 288T 110 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 111: ...GS 8P 288T Chapter 1 Appliance installation 111 Figure 64 GS 8P 288T Rear ...
Страница 112: ...GS 8P 288T 112 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 113: ...GS 8P 288T Chapter 1 Appliance installation 113 ...
Страница 114: ...GS 8P 288T 114 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 115: ...GS 8P 288T Chapter 1 Appliance installation 115 ...
Страница 116: ...GS 8P 288T 116 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 117: ...GS 8P 288T Chapter 1 Appliance installation 117 ...
Страница 118: ...GS 8P 288T 118 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 119: ...GS 8P 288T Chapter 1 Appliance installation 119 ...
Страница 120: ...GS 8P 288T 120 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 124: ...GS 8P 288T 124 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 65 GS 8P 288T Rear ...
Страница 125: ...GS 8P 288T Chapter 1 Appliance installation 125 ...
Страница 126: ...GS 8P 288T 126 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 127: ...GS 8P 288T Chapter 1 Appliance installation 127 ...
Страница 128: ...GS 8P 288T 128 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 129: ...GS 8P 288T Chapter 1 Appliance installation 129 ...
Страница 130: ...GS 8P 288T 130 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 131: ...GS 8P 288T Chapter 1 Appliance installation 131 ...
Страница 132: ...GS 8P 288T 132 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 133: ...GS 8P 288T Chapter 1 Appliance installation 133 ...
Страница 137: ...GS 8P 192T Chapter 1 Appliance installation 137 Figure 67 GS 8P 192T Front ...
Страница 181: ...How to install the SFPs Chapter 1 Appliance installation 181 Figure 101 2U capture card port assignments ...