Sensor deployment types

We just looked at uniflow and bitflow. Let's discuss the FRP deployment and architectures followed for smooth network analysis. Generally, the FRP components are connected to a network in the setup shown in the following diagram:

The preceding diagram highlights the sensor deployment in a network where the sensor is a part of the router, and through a dedicated channel, it transports logs to the collector from where they are stored to the storage units. The storage units are further connected to the analyzer for in-depth analysis. The architecture can vary from one type to another, such as for host-flow, perimeter, and enclave visibility.

We will denote the FRP system through a single icon, as shown in preceding diagram. We can see that FRP is placed in between the firewall and the internal router. The setup demonstrates the usage for perimeter visibility. Similarly, enclave (switch level) visibility can be achieved by placing the sensors on most of the switches and then aggregating the records:

Host-flow visibility can be achieved by placing the sensor right on the endpoint itself and then aggregating the records:

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset