Contact Sales
Contact Sales

Asset-Aware Network Monitoring

Asset-Aware Network Monitoring (PDF, 1.20MB)Published: 26 Mar, 2026
Created by:
Brian Bitner

Industrial Control Systems (ICS) often use technologies that do not support active scanning, patching, or traditional endpoint security controls. As a result, defenders must rely on compensating detective controls that minimize interference with operational assets.

This research demonstrates how passive network security monitoring can detect unauthorized devices and communications by comparing observed network traffic against documented asset inventory data. Using a custom Zeek script, a proof-of-concept detection framework enforces asset inventory expectations while analyzing live network traffic.

The results show that asset-aware network monitoring can identify anomalous behavior, including unauthorized services and access paths, and serves as a practical compensating control in environments where endpoint security and active scanning are infeasible.