Network Detection Suspicious Protocols
The Network Detection - Suspicious Protocols insight displays anomalies detected in network traffic. This feature monitors network traffic to identify any communication attempts to new countries, specifically looking for suspicious protocols. It helps administrators to identify and address suspicious protocols. For each client, the baseline for historical data uploads is first established over a 30-day period. Based on the client-specific baseline, this feature automatically detects and flags abnormally large data uploads using suspicious protocols. If no anomaly is detected, this insight is not displayed in the Insights page.
To access the insight, complete the following steps:
-
Access the Insights page. For more information, see Accessing Insights Page.
-
Click the Network Detection - Suspicious Protocols tile.
Figure 1: Network Detection - Suspicious Protocols Insight
The Network Detection - Suspicious Protocols metrics displays the client information where the anomaly was triggered.
-
Select the client to see more details.
Figure 2: Behavior Mapping
In the Behavior Mapping chart, you can view the details of the anomaly. Hover over the chart to see each client's share of historical traffic and anomalies.
Note:A few protocols are pre-populated for the baseline. The triangle next to the protocol denotes the anomaly.
The Suspicious Uploads table lists all the anomalies detected for the client. You can view the details of the anomaly:
-
Source Role—Displays the role assigned to the client.
-
Destination—Displays the country name from where the records were uploaded using suspicious protocols.
-
Protocol—Displays the
suspicious protocol.
-
Port—Displays port used to upload the abnormal data using suspicious protocols.
-
Usage—Displays the value of uploaded data.
Note:Only abnormal data with a file size of 10 KB and above will trigger this anomaly.
-
Date—Displays the date when the anomaly was detected.
-