How does Bro analyze the traffic?
First Bro filters the traffic, discarding elements of minimal important to its analysis. The remaining information is sent to its “event” engine, where Bro interprets the structure of the network packets and abstracts them into higher-level events describing the activity. Finally, Bro executes policy scripts against the stream of events, looking for activity that the rules indicate should generate alerts or actions, such as possible intrusions.
Related Questions
- There are various departments in our company and each of them belongs to a different VLAN. Can Colasoft Capsa analyze traffic of each department and how?
- How can I use Colasoft Capsa to analyze traffic on other switch ports if our network is tied together with a switch?
- Can Colasoft Capsa analyze the traffic occupation in the network?