|
Network Anomaly Control
Detection of an anomaly in a network refers to the identification of abnormal behaviors as attacks. In a normal system, users’ requests are consistent with predictable statistical values. What is essential is to identify and describe a normal behavior pattern. It only becomes possible to spot any existing anomalies after this phase. Normal behavior can be modeled with dispersion or with dispersion moments. It can be defined within a set of rules or various other methods may be applied, but in the end any deviation from a defined or learnt behavior must be considered a threat and may also be classified as an attack according to the degree of deviation. The main advantage of this approach is the possibility of discovering new, previously unknown attacks. The disadvantage is the high number of false alarms.
BizNet offers solutions for Network Anomaly Control using:
- McAfee Network User Behavior (Security) Analysis
- Arbor Networks
|