Deployment Guide
v5.0
Search this version
Deployment Guide
Deployment Guide
Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
Analysis Methods Performed by Sensors
Copy Markdown
Open in ChatGPT
Open in Claude
The Sensor performs multiple layers of analysis in real time:
- Signature-Based Detection: Traditional Suricata rules (ET Pro + custom) with fast_pattern and rich metadata.
- Machine Learning-Based Anomaly Detection: Random Cut Forests, Isolation Forests (and evaluated alternatives) on protocol features (DNS entropy/volume, HTTP UA anomalies, TLS handshake timing) as well as netflow statistics.
- Behavioral Anomaly Detection: RisingWave materialized views for behavioral-based detection.
- Statistical Anomaly Detection: Netflow analysis for exfiltration (bytes out/in ratio) and long-duration connections.
- Protocol Anomaly Detection: Malformed packets, unusual handshake timing, ALPN mismatches.
- High-Fidelity Threat Intelligence: Real-time matching against C2, TI, and OSINT feeds (IPs, domains, URLs, hashes).
Encrypted Traffic Analysis (performed even without decryption keys):
- Statistical analysis of netflow (packet/byte ratios, inter-packet timing).
- TLS certificate analysis (validity period, subject/issuer anomalies, chain length).
- IP analysis and matching to threat intelligence (suspicious ASNs, countries, known C2 infrastructure).
- JA3 and JA4 fingerprinting of client and server TLS parameters.
VariableType to search · ESC to discard
GlossaryType to search · ESC to discard
InsertType to search · ESC to discard
No matches
Last updated on
Was this page helpful?
Next to read:
Encrypted Traffic Visibilitynull
Discard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message