- How It Works
- How It Works
- Identifiable Threats
- How NETSCOUT Helps
Robert Derby
Senior Security Product Marketing Manager
Understanding Network Behavior Analysis Systems
A Network Behavior Analysis (NBA) system monitors network traffic to identify unusual communication patterns that may indicate a security threat. By analyzing how devices, applications, and systems communicate, NBA helps security teams identify suspicious activity that traditional signature-based detection methods may miss.
Network behavior analysis remains a useful security technique and is commonly incorporated into broader Network Traffic Analysis (NTA) and Network Detection and Response (NDR) solutions.
How Does Network Behavior Analysis Work?
NBA systems examine network traffic characteristics, including communication patterns, connection frequency, traffic volumes, protocols, and source and destination addresses.
Many systems establish a baseline of expected network behavior and identify deviations that warrant investigation. Depending on the technology, analysis may use network flow records, packet data, statistical models, or machine learning.
Because legitimate network activity changes over time, an anomaly does not necessarily indicate an attack. Security teams must evaluate the surrounding context to determine whether the activity presents a threat.
What Threats Can Network Behavior Analysis Help Identify?
NBA can help security teams recognize activity associated with:
- Lateral movement: Unexpected communication between internal systems or network segments.
- Data exfiltration: Unusual outbound transfers or communication with unfamiliar destinations.
- Network reconnaissance: Port scanning and other patterns associated with probing systems.
- Malware activity: Suspicious communication patterns, including potential command-and-control traffic.
- Policy violations: Network communications that deviate from established access expectations.
The effectiveness of these detections depends on network visibility, available telemetry, and the analytics used.
How Does NETSCOUT Support Network Behavior Analysis?
NETSCOUT Omnis Cyber Intelligence incorporates behavioral analytics within its NDR platform.
CyberStream and vCyberStream sensors use deep packet inspection to analyze network activity at the source of capture. Omnis Cyber Intelligence combines behavioral analytics with other detection techniques, including threat intelligence, signatures, and policy violations.
Continuous packet capture and packet-derived metadata provide historical evidence that analysts can use to investigate suspicious activity, examine related communications, and determine the scope of a potential incident.