Network Baseline
https://www.scnsoft.com/blog/detecting-apt-activity-with-network-traffic-analysis

Network Baseline

What is it?

A network baseline is a set of metrics that describe normal operating parameters. The events and alarms generated during this period represent currently normal behaviour “snapshot” in time.

Of course, there may be things you want to filter out right away but in general you should resist the temptation and wait until you have had a chance to observe patterns in your network.

Network performance monitors (NPMs) continuously listen on your network to establish a baseline to judge your network by and real time monitoring to identify anomalies.


?Why do we need it?

Setting the baseline enables engineers to catch anomalies in traffic. An anomaly can be where a spike from the baseline is detected. This may indicate a security breach, device failure, application performance issue or simply an authorized user downloading a large file.

Baselining lets network operations understand the “before” and “after” when a change is made, making it easier to measure benefits and calculate ROI.

Baselining provides data on network recourse allocation and security management to support decision making.

Network baselining can enable us ensure quality of experience (QoE) for our customers. For example if we provide Voice Call services to our customer, setting up metrics to ensure quality is necessary. If a metric of 4 is business quality and a metric of 4.6 is our baseline, when we notice a drop from 4.6 to 4.2 we can diagnose the issue and take corrective action proactively before the users are impacted by poor quality calls.


How do we set up a network baseline?

Providing a network baseline requires testing and reporting of the physical connectivity, normal network utilization, protocol usage, peak network utilization and average throughput of the network usage. Such in-depth network analysis is required to identify vulnerabilities and issues with speed.

While setting up the baseline, answering the following questions is necessary:

·        What is normal file access?

·        What is normal VPN activity for a given user?

·        What is normal network activity for an organizational unit?

·        What is an average employee’s work schedule?

An organisations baseline will be as unique as the users who generated the traffic.

Once a baseline is established, organisations can use this information to determine both present and future network upgrade needs as well as assist in making changes to ensure their current network is optimized for peak performance.


What are the benefits of network baselining?

·        Allows us to determine “normal” behaviour thus anomalies can easily be detected.

·        It facilitates the evaluation and optimization of costs associated with the platform.

·        Given a specific requirement on the platform, a baseline can allow us to evaluate whether or not the platform can satisfy that requirement.

·        Can facilitate the analysis associated with the introduction of a change in the platform, providing us with a before and after vision of the change.

·        It allows preventive action to be taken, i.e. to anticipate performance problems even before users complain or an alarm is triggered.


This information was sourced but no limited to:

https://blog.silver-peak.com/the-importance-of-setting-network-baselines

https://www.webopedia.com/TERM/N/network_baselining.html

https://pandorafms.com/blog/network-baseline/

要查看或添加评论,请登录

社区洞察

其他会员也浏览了