{"id":90228,"date":"2020-07-30T01:42:34","date_gmt":"2020-07-29T23:42:34","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/stealthwatch-analiz-i-rassledovanie-inczidentov-chast-3"},"modified":"2020-07-30T01:42:34","modified_gmt":"2020-07-29T23:42:34","slug":"stealthwatch-analiz-i-rassledovanie-inczidentov-chast-3","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-analiz-i-rassledovanie-inczidentov-chast-3","title":{"rendered":"StealthWatch: incident analysis and investigation. Part 3","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/3efab47dd80ed8bd6a81dbca5bedcc72.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/katalog\/cisco\/cisco-stealthwatch\">Cisco StealthWatch<\/a><\/noindex> is an analytical solution in the field of cybersecurity that provides comprehensive threat monitoring in a distributed network. The core of StealthWatch's operation involves the collection of NetFlow and IPFIX from routers, switches, and other network devices. As a result, the network becomes a sensitive sensor, allowing administrators to see beyond the reach of traditional network security methods, such as Next Generation Firewall.<\/p>\n<p>In previous articles, I have already written about StealthWatch: <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/458626\/\">initial presentation and capabilities<\/a><\/noindex>, as well as <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/461831\/\">deployment and configuration<\/a><\/noindex>. Now, I suggest moving forward and discussing how to work with alarms and investigate security incidents generated by the solution. I will provide 6 examples that I hope will give a good indication of the product's usefulness.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nFirst, it should be noted that StealthWatch has a certain distribution of triggers across algorithms and feeds. The former are different types of alarms (notifications), which, when triggered, can reveal suspicious activity in the network. The latter are security incidents. This article will cover 4 examples of algorithm triggers and 2 examples of feeds.<\/p>\n<h2>1. Analyzing the most significant interactions within the network<\/h2>\n<p>\nThe initial step in configuring StealthWatch is to define hosts and networks by groups. In the web interface, the tab <i>Configure &gt; Host Group Management<\/i> should be used to sort networks, hosts, and servers into their respective groups. Custom groups can also be created. By the way, analyzing interactions between hosts in Cisco StealthWatch is quite convenient, as not only can search filters for flows be saved, but also the results themselves.<\/p>\n<p>To start, you should navigate to the tab in the web interface <i>Analyze &gt; Flow Search<\/i>. Then, you should set the following parameters:<\/p>\n<ul>\n<li>Search Type \u2014 Top Conversations (most popular interactions)<\/li>\n<li>Time Range \u2014 24 hours (time interval, another can be used)<\/li>\n<li>Search Name \u2014 Top Conversations Inside-Inside (any meaningful name)<\/li>\n<li>Subject \u2014 Host Groups \u2192 Inside Hosts (source \u2014 group of internal nodes)<\/li>\n<li>Connection (you can specify ports, applications)<\/li>\n<li>Peer \u2014 Host Groups \u2192 Inside Hosts (destination \u2014 group of internal nodes)<\/li>\n<li>In Advanced Options, you can additionally specify the collector from which the data is viewed, the sorting output (by bytes, flows, etc.). I will leave it as default.<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/fefc6d925ab3b155aeea2536dddaf7da.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAfter clicking the button <i>Search <\/i>a list of interactions is provided, which are already sorted by the volume of transmitted data.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/3fa739dec55bd4a564ee78adc2ae0e91.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIn my example, the host <i>10.150.1.201<\/i> (server) transmitted<i> 1.5 GB<\/i> traffic to the host <i>10.150.1.200<\/i> (client) via the <i>mysql<\/i>protocol. The button <i>Manage Columns<\/i> allows you to add more columns to the displayed data.<\/p>\n<p>Next, at the administrator's discretion, a custom rule can be created that will constantly trigger for such interactions and notify via SNMP, email, or Syslog. <\/p>\n<h2>2. Analyzing the slowest client-server interactions within the network for latency<\/h2>\n<p>\nTags <b>SRT (Server Response Time)<\/b>, <b>RTT (Round Trip Time)<\/b> allow you to determine server delays and overall network latency. This tool is especially useful when you need to quickly identify the causes of user complaints about slow-running applications.<\/p>\n<p><i>Note<\/i>: almost all Netflow exporters <b>cannot<\/b> send SRT, RTT tags, so often to see such data on FlowSensor, you need to configure the traffic copy sending from network devices. FlowSensor, in turn, provides extended IPFIX to FlowCollector.<\/p>\n<p>It is more convenient to conduct this analytics in the Java application StealthWatch, which is installed on the administrator's computer.<\/p>\n<p>Right-click on <i>Inside Hosts<\/i> and go to the tab <i>Flow Table<\/i>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/3a23cf8219fc2ad44eeab7da27d5e696.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nClick on <i>Filter <\/i>and set the necessary parameters. For example:<\/p>\n<ul>\n<li>Date\/Time \u2014 For the last 3 days<\/li>\n<li>Performance \u2014 Average Round Trip Time &gt;=50ms<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/c7c717e336dc96fce48f05bc735cd14a.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/a0aad8dfa8e759f22486716221ddac82.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAfter displaying the data, you should add the desired RTT, SRT fields. To do this, click on the column in the screenshot and right-click to select <i>Manage Columns<\/i>. Then click on the RTT, SRT parameters.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/069660512595d149353ea98b9fb7c828.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAfter processing the request, I sorted by RTT average and saw the slowest interactions.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/669e24fabc650d607b4767c50345a12b.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nTo drill down into detailed information, right-click on the flow and select <i>Quick View for Flow<\/i>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/6e03114b9cdbbef516d65cdc43c6b3e2.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThis information indicates that the host <i>10.201.3.59<\/i> from the group <i>Sales and Marketing<\/i> via the <i>NFS<\/i> calls <i>has been sending data to the DNS server<\/i> for 1 minute and 23 seconds with just terrible latency. In the tab <i>Interfaces <\/i>you can find out from which Netflow exporter the data was received. The tab <i>Table <\/i> displays more detailed information about the interaction.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/66750a2e003972cabdea60096397f8be.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNext, you should find out which devices are sending traffic to FlowSensor, and the problem is likely there.<\/p>\n<p>Moreover, StealthWatch is unique in that it performs <b>deduplication<\/b> data (combines the same streams). Consequently, it is possible to collect from almost all Netflow devices without worrying about excessive duplicate data. On the contrary, this scheme helps identify where the most significant delays occur.<\/p>\n<h2>3. Audit of HTTPS Cryptographic Protocols<\/h2>\n<p>\n<b>ETA (Encrypted Traffic Analytics)<\/b> \u2014 a technology developed by Cisco that allows for the detection of malicious connections in encrypted traffic without decryption. Moreover, this technology enables detailed analysis of HTTPS versions TLS and cryptographic protocols used during connections. This functionality is particularly useful for identifying network nodes that utilize weak cryptographic standards.<\/p>\n<p><i>Note<\/i>: before proceeding, the network app must be installed on StealthWatch \u2014 <b>ETA Cryptographic Audit<\/b>.<\/p>\n<p>We go to the <i>Dashboards \u2192 ETA Cryptographic Audit<\/i> and select the group of hosts to analyze. For an overview, let\u2019s choose <i>Inside Hosts<\/i>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/2cac9b02089c027cc7908ce018638a68.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIt can be observed that the TLS version and the corresponding cryptographic standard are displayed. Following the familiar layout in the column <i>Actions <\/i>we proceed to the <i>View Flows<\/i> and a search will start in a new tab.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/0b0a274b1538e58ad74a17e2a4eee160.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/ad99bdd25cd02247b6e76240fdd7edd6.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nFrom the output, it is evident that the host <i>198.19.20.136<\/i> has used HTTPS with TLS 1.2 for <i>12 hours<\/i> where the encryption algorithm <i>AES-256<\/i> and hash function <i>SHA-384<\/i>. Thus, ETA helps identify weak algorithms in the network.<\/p>\n<h2>4. Network Anomaly Analysis<\/h2>\n<p>\nCisco StealthWatch can recognize traffic anomalies in the network using three tools: <b>Core Events<\/b> (security events), <b>Relationship Events<\/b> (events of interactions between segments, network nodes) and <b>behavioral analysis<\/b>.<\/p>\n<p>Behavioral analysis, in turn, allows for constructing a behavioral model for a specific host or group of hosts over time. The more traffic passes through StealthWatch, the more accurate the triggers will be thanks to this analysis. Initially, the system may trigger incorrectly often, so the rules need to be manually adjusted. I recommend not paying attention to these events for the first few weeks, as the system will self-tune, or alternatively, add these to exceptions.<\/p>\n<p>Below is an example of a pre-configured rule <i>Anomaly<\/i>, which states that the event will trigger without an alarm if <i>a host in the Inside Hosts group interacts with a group of Inside Hosts and the traffic exceeds 10 megabytes in 24 hours.<\/i>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/9f13165149dfab7e6cf5cf038e1573e5.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nFor example, let\u2019s take the alarm <i>Data Hoarding<\/i>, which means that some source\/destination host downloaded\/uploaded an unusually large amount of data from a group of hosts or a host. We click on the event and drill down into the table where the triggering hosts are specified. Next, we select the host of interest in the column <i>Data Hoarding<\/i>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/5bac3325f9f34342802d115c4a13bf39.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/5e065344005db20d276a800d8362a347.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAn event is displayed, indicating that 162k 'points' were detected, while the policy allows for 100k 'points' \u2014 these are internal metrics of StealthWatch. In the column <i>Actions <\/i>click <i>View Flows<\/i>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/352df8d925fe46246a35677482d65030.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWe can observe that <i>the host<\/i> interacted overnight with the host <i>10.201.3.47<\/i> from the department <i>Sales &amp; Marketing<\/i> via the <i>HTTPS <\/i>and downloaded <i>1.4 GB<\/i>. This example may not be entirely successful, but the detection of interactions involving several hundred gigabytes is carried out in exactly the same way. Therefore, further investigation of anomalies may lead to interesting results.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/923992706b36b18d2709feb444f7cf14.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<i>Note<\/i>: in the SMC web interface, data in the tabs <i>Dashboards <\/i>is displayed only for the last week, and in the tab <i>Monitor<\/i> for the last 2 weeks. To analyze older events and to generate reports, you need to work with the Java console on the administrator's computer.<\/p>\n<h2>5. Finding internal network scans<\/h2>\n<p>\nNow let's consider a few examples of feeds \u2014 security incidents. This functionality is of more interest to security experts.<\/p>\n<p>There are several predefined types of scanning events in StealthWatch:<\/p>\n<ul>\n<li>Port Scan \u2014 the source scans multiple ports of the destination node.<\/li>\n<li>Addr tcp scan \u2014 the source scans an entire network on the same TCP port, changing the destination IP address. During this, the source receives TCP Reset packets or does not receive any responses at all.<\/li>\n<li>Addr udp scan \u2014 the source scans an entire network on the same UDP port, changing the destination IP address. During this, the source receives ICMP Port Unreachable packets or does not receive any responses at all.<\/li>\n<li>Ping Scan \u2014 the source sends ICMP requests to an entire network in order to seek responses.<\/li>\n<li>Stealth Scan tcp\/udp \u2014 the source used the same port to connect to multiple ports on the destination node at the same time.<\/li>\n<\/ul>\n<p>\nFor more convenient finding of all internal scanners at once, there is a network app for <i>StealthWatch \u2014 Visibility Assessment<\/i>. By going to the tab <i>Dashboards \u2192 Visibility Assessment \u2192 Internal Network Scanners<\/i> you will see security incidents related to scanning from the last 2 weeks.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/eb72d246b44752e8441afd500178fc02.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nClicking the button <i>Details<\/i>, the beginning of the scanning of each network, traffic trends, and corresponding alarms will be visible.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/b4ef9ec46040cdab026b83d03eda615f.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nYou can then \u201cdive\u201d into the host from the tab in the previous screenshot and see security events, as well as activity for the past week for this host.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/7f8d57e2d29930fcd5febf5a44cca714.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/7ce0e489618c072958a3416e342900eb.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nFor example, let's analyze the event <i>Port Scan<\/i> from the host <i>10.201.3.149<\/i> to <i>10.201.0.72<\/i>, by clicking on <i>Actions &gt; Associated Flows<\/i>. This initiates a search through the flows and relevant information is displayed.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/07f86540fae01171c8dfea68c8451a47.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAs we can see, this host from one of its ports <i>51508\/TCP<\/i> scanned the destination host 3 hours ago on ports<i> 22, 28, 42, 41, 36, 40 (TCP)<\/i>. Some fields do not display information either because not all Netflow fields are supported on the Netflow exporter.<\/p>\n<h2>6. Analyzing downloaded malware using CTA<\/h2>\n<p>\n<b>CTA (Cognitive Threat Analytics)<\/b> is Cisco's cloud analytics that integrates seamlessly with Cisco StealthWatch and enhances signature-less analysis with signature-based analysis. This enables the detection of Trojans, network worms, zero-day malware, and other threats as well as their spread within the network. The previously mentioned ETA technology also allows for the analysis of such malicious communications even in encrypted traffic.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/68d86dc9686e2f0c754181db73411ab8.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nLiterally on the very first tab in the web interface, there is a special widget <i>Cognitive Threat Analytics<\/i>. A brief summary indicates the detected threats on user hosts: Trojan, malware, adware. The word \u201cEncrypted\u201d indicates the operation of ETA. Clicking on the host reveals all the information, including security events and logs for CTA.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/a49a2ae655c1dfa89cdcb194c8f38c51.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/f6bbe9585060ecb46712584924125fa3.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHovering over each CTA stage displays detailed information about the interactions. For complete analysis, you should click <i>View Incident Details<\/i>, and you will be taken to a separate console. <i>Cognitive Threat Analytics<\/i>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/8737a4da2133ee4b72e830f9208f4d11.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIn the top right corner, the filter allows you to display events by severity level. Hovering over a specific anomaly brings up logs with the corresponding timeline on the right side of the screen. Thus, the cybersecurity specialist clearly understands which infected host started taking actions after which actions.<\/p>\n<p>Below is another example\u2014a banking Trojan that infected the host <i>198.19.30.36<\/i>. This host began interacting with malicious domains, and the logs display information about the flows of those interactions. <\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/d5faba6e8ec2addff8e18b83548e65fe.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<img decoding=\"async\" alt=\"StealthWatch: incident analysis and investigation. Part 3\" src=\"\/wp-content\/uploads\/2020\/07\/a5f880407468b6fc62805d68c2d672cb.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNext, one of the best solutions that can be is to quarantine the host using native <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/511726\/\">integration <\/a><\/noindex>with Cisco ISE for further treatment and analysis. <\/p>\n<h2>Conclusion<\/h2>\n<p>\nThe Cisco StealthWatch solution is among the leaders in network monitoring products in terms of network analysis and information security. With it, you can detect illegitimate interactions within the network, application delays, the most active users, anomalies, threats, and APTs. Moreover, you can find scans, penetration testers, and conduct crypto audits of HTTPS traffic. You can find even more use cases at <noindex><a rel=\"nofollow\" href=\"https:\/\/cisco.bravais.com\/s\/lnmF3Eowwg51t7Rj9DtD\">this link<\/a><\/noindex>.<\/p>\n<p>If you wish to check how smoothly and efficiently everything is operating in your network, send <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/katalog\/cisco\/cisco-stealthwatch\">the ticket<\/a><\/noindex>. <br \/>\nWe plan to publish several more technical articles on various cybersecurity products soon. If you're interested in this topic, keep an eye on updates on our channels (<noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/tssolution\">Telegram<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.facebook.com\/tssolution2020\/\">Facebook<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/ts_solution\">VK<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/blog\">TS Solution Blog<\/a><\/noindex>)!<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/509812\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>Cisco StealthWatch \u2014 \u044d\u0442\u043e \u0430\u043d\u0430\u043b\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0435 \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u0418\u0411, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u0432\u0441\u0435\u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u0439 \u043c\u043e\u043d\u0438\u0442\u043e\u0440\u0438\u043d\u0433 \u0443\u0433\u0440\u043e\u0437 \u0432 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u0441\u0435\u0442\u0438. \u0412 \u043e\u0441\u043d\u043e\u0432\u0435 \u0440\u0430\u0431\u043e\u0442\u044b StealthWatch \u043b\u0435\u0436\u0438\u0442 \u0441\u0431\u043e\u0440 NetFlow \u0438 IPFIX \u0441 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u043e\u0432, \u043a\u043e\u043c\u043c\u0443\u0442\u0430\u0442\u043e\u0440\u043e\u0432 \u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432. \u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0441\u0435\u0442\u044c \u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u0441\u044f \u0447\u0443\u0432\u0441\u0442\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u043c \u0441\u0435\u043d\u0441\u043e\u0440\u043e\u043c \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0443 \u0437\u0430\u0433\u043b\u044f\u043d\u0443\u0442\u044c \u0442\u0443\u0434\u0430, \u043a\u0443\u0434\u0430 \u043d\u0435 \u043c\u043e\u0433\u0443\u0442 \u0434\u043e\u0431\u0440\u0430\u0442\u044c\u0441\u044f \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u0435 \u043c\u0435\u0442\u043e\u0434\u044b \u0437\u0430\u0449\u0438\u0442\u044b \u0441\u0435\u0442\u0438, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, Next Generation [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":90229,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-90228","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-analiz-i-rassledovanie-inczidentov-chast-3\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47StealthWatch: \u0430\u043d\u0430\u043b\u0438\u0437 \u0438 \u0440\u0430\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0435 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u043e\u0432. \u0427\u0430\u0441\u0442\u044c 3 | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-analiz-i-rassledovanie-inczidentov-chast-3\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-07-29T23:42:34+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-07-29T23:42:34+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47StealthWatch: Incident Analysis and Investigation. Part 3 | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-analiz-i-rassledovanie-inczidentov-chast-3","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47StealthWatch: \u0430\u043d\u0430\u043b\u0438\u0437 \u0438 \u0440\u0430\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0435 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u043e\u0432. \u0427\u0430\u0441\u0442\u044c 3 | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-analiz-i-rassledovanie-inczidentov-chast-3","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-07-29T23:42:34+00:00","article:modified_time":"2020-07-29T23:42:34+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"90228","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:55:29","updated":"2022-10-02 06:01:42","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/90228","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=90228"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/90228\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/90229"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=90228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=90228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=90228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}