Section 29: Indicators of Compromise Flashcards

1
Q

Switched Port Analyzer (SPAN)

A

Allows for the copying of ingress and/or egress communications from one or more switch ports to another

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NetFlow

A

▪ A Cisco-developed means of reporting network flow info to a structured database

● Protocol interface
● IP version/type
● Source/destination IP
● Source/destination port
● IP service type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Flow Analysis vs Full Packet Capture

A

o Full Packet Capture (FPC)
▪ Captures the entire packet, including the header and the payload for all traffic entering and leaving a network

o Flow Analysis
▪ Relies on a flow collector, which records metadata and statistics rather than recording each frame that passes through the network

Flow analysis does not provide the actual content of the traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Zeek

A

Passively monitors a network like a sniffer, but only logs full packet
capture data of potential interest

▪ Performs normalization of the data and stores it as a tab-delimited or JSON-formatted text files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Multi Router Traffic Grapher (MRTG)

A

Multi Router Traffic Grapher (MRTG)

▪ Creates graphs showing traffic flows through the network interfaces of routers and switches by polling the appliances using SNMP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

File Integrity Monitoring (FIM)

A

▪ A host-based IDS that creates a hash digest for every file being monitored on the given system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly