Flashcards in SECOPS 2: NSM Tools and Data Deck (11)
Summary data for network connections. Who talked to whom and when. Like a phone bill.
5 Tuple with timestamps
Full Packet Capture format
Full content data
aka full packet capture
Details associated with requests and responses.
Example: Client GET request and server response
Typically from IPS. Network traffic matches conditions to generate alert.
Statistics derived from NSM data
Statistical data over time produces...
what is normal
Deviations from normal
Data about data.