Network Behavioral Anomaly Detection (NBAD)
Network Behavioral Anomaly Detection (NBAD)
NBAD Overview
Activity Table
Event Report
Pattern Details
Other Graphs
Examples
2
NBAD Events
3
Network Behavioral Anomaly Detection
4
NBAD Anomaly Types
Type Description
5
Other Other (not TCP, UDP or ICMP) flood
April 22, 2023
Email Notifications
6
Agenda
NBAD Overview
Activity Table
Event Report
Pattern Details
Other Graphs
Examples
7
NBAD/Flood Activity
Line indicates
Outgoing size of
UDP Flood parameter
8
NBAD/Flood Activity:
Filtering the Information Displayed
9
Agenda
NBAD Overview
Activity Table
Event Report
Pattern Details
Other Graphs
Examples
10
Event Report
11
Event Report:
Flood Summary
Example #1
A strong outgoing unr flood
Lasted for 43mins – now ended
Malformed Packets with 5 flood
patterns for analysis
Example #2
A strong incoming TCP SYN flood
Still active after 24mins
DDoS attack with 5 different flood
patterns for analysis
12
Event Report:
Statistics
Example #1
High volume of traffic deviates
from the expected behavior
model
Example #2
Relatively low volume of
traffic deviates from the
expected behavior model
13
Event Report:
Charts
Example #1
Deviation of observed outgoing
unr traffic from expected model
Ratio of TX UNR to RX (IPv4)
Example #2
Deviation of observed
incoming TCP syn packet
rate from expected model
Ratio of is “incoming TCP
syn” to “outgoing tcp fin”
14
Event Report:
Patterns
Number of
consistent bytes in
header / payload
SRC IP : SRC PORT > DEST IP : DEST PORT PROT SIG LENGTH
15
Event Report:
Packet Captures
Number of
packets
Deviation from
expected behavior Download
Capture
NBAD Overview
Activity Table
Event Report
Pattern Details
Other Graphs
Examples
17
Pattern
Flood Summary
Pattern Summary
Filter Rule
Full Pattern
Pattern Chart
Packet Captures
Top TX Hosts
Top RX Hosts
18
Pattern Summary
19
Filter Rule
20
Full Pattern
21
Pattern Chart
Top transmitting
Hosts (up to 20)
23
Packet Captures
Analyze Flow
Analyze Host
24
Packet Captures
Ethereal
25
Agenda
NBAD Overview
Activity Table
Event Report
Pattern Details
Other Graphs
Examples
26
NBAD Trends
27
NBAD Distribution: Duration
28
NBAD Distribution: Bit Rate
29
NBAD Top Sources
30
NBAD Top Targets
31
Agenda
NBAD Overview
Activity Table
Event Report
Pattern Details
Other Graphs
Examples
32
Example #1: Event 529
33
1) Attack Under Way
34
2) More Events Added To Flood
35
3) Attack Has Ceased
36
Full Pattern
37
Pattern Chart
38
Many TX Hosts – 1 RX Host
Conclusion: Classic DDoS Attack
Many TX
Hosts
Single RX
Host
39
Example #2: Event 540
40
Event Report
41
Pattern 2672
42
1 TX Host – Many RX Hosts
Conclusion: Classic Scan Profile
Single TX
Host
Many RX
Hosts
43
Review Question
Were there any suspected DDoS attacks on the Silver Group over
the displayed time period?
?
Flood ID: 99913
44
Review Question
Hands on practice
detecting NBAD events
46