Talk With an Expert

Network Inspection of Duplicate Packets

Network Inspection of Duplicate Packets (PDF, 4.32MB)Published: 11 Nov, 2016
Created by:
Randy Devlin

Network Intrusion Analysis enables a security analyst to review network traffic for protocol conformity and anomalous behavior. The analyst's goal is to detect network intrusion activity in near-real time. The detection provides details as to who the attackers are, the attack type, and potential remediation responses. Is it possible that a network security stack could render the analyst blind to detecting intrusions? This paper will review architecture, traffic flow, and inspection processes. Architecture review validates proper sensor placement for inspection. Traffic flow analyzes sources and destinations, approved applications, and known traffic patterns. Inspection process evaluates protocols and packet specific details. The combination of these activities can reveal scenarios that potentially result in limitations of network security inspection and analysis.