Whats the advantage of network based audit against host based audit?
The recorded data are collected from network directly, with little potential to be tampered or modified purposely, compared against those host based audit systems which collect log files from the hosts that might be compromised. Additionally, with SA, its not necessary to install agents on hosts so that the potential impact to hosts is minimized. Another obvious advantage of SA is its simple implementation and strong flexibility.