Nsm is the collection detection and analysis of network security data.
Bro network security monitor review.
Those who know security use zeek.
The bro network security monitor bro is a network based analysis framework.
Vern paxson began developing the project in the 1990s under the name bro as a means to understand what was happening on his university and national laboratory networks.
Information security has traditionally been divided into many different focus areas but i tend to lean most towards the way the united states department of defense us dod categorizes the domains of computer network defense cnd per dod 8500 2.
Bro s powerful analysis engine makes it adept at high performance network monitoring protocol analysis and real time application layer state information.
Bro detects intrusions by first parsing network traffic to extract is application level semantics and then executing event oriented analyzers that compare the activity with patterns.
Zeek has a long history in the open source and digital security worlds.
Bro network security monitor bro is a network intrusion detection system nids that passively monitors network traffic and looks for suspicious activity.
The product works very good so long as one knows the absolutes of networking.
This makes bro a very good intrusion detection system ids and network analysis framework.