Why deploy Network Behavior Analysis?
NBA, also known as Network Behavior Anomaly Detection, describes a relatively new field of products that employ passive observation and profiling to spot traffic spikes, atypical usage and policy violations. Conventional intrusion prevention system solutions like Snort and Intrusion.com defend your network’s perimeter through in-line traffic inspection, signature detection and real-time blocking. However, NBA solutions watch what’s happening inside your network, aggregating flow data from many points to support offline behavioral analysis, relationship profiling, anomaly identification and human-assisted “soft touch” remediation. By operating passively, NBA avoids latency or becoming a performance bottleneck. By monitoring traffic flows inside your network, NBA can detect employee use of forbidden protocols and behind-the-firewall connections of infected laptops and removable storage. By comparing current behavior with past behavior, NBA can spot zero-day attacks and worm outbreaks for