How does a SOC leverage flow collectors?
A flow collector (such as Cisco Secure Network Analytics, formerly Stealthwatch) is a critical tool within a Security Operations Center (SOC) for providing 'pervasive visibility' into the network. Instead of capturing every full packet---which is resource-intensive---a flow collector ingests NetFlow or IPFIX data, which contains metadata like source/destination IPs, ports, and the volume of data transferred.
The SOC leverages this data for threat detection and response by establishing a baseline of normal network behavior. When a flow collector identifies an anomaly---such as an endpoint suddenly sending gigabytes of data to an unusual external IP (data exfiltration) or scanning internal ports (lateral movement)---it flags the incident for analysis. Unlike Real-time content filtering (Option D), which happens at the gateway (e.g., Cisco Umbrella or WSA), flow collectors provide a historical record and behavioral analysis of all internal and external traffic. They do not perform load balancing (Option B) or backup/recovery (Option A). In the Cisco SDSI framework, flow analysis is essential for identifying the 'unknown unknowns' and providing the forensic evidence needed to understand the scope and path of a security breach.
Roosevelt
3 days agoLarae
8 days agoDonette
13 days agoKirk
19 days agoOliva
24 days agoRosendo
29 days agoLeah
1 month agoPenney
1 month agoAngelo
1 month agoDorcas
2 months agoDahlia
2 months agoBilli
2 months agoCordelia
2 months agoDeja
2 months agoHelene
4 months agoDwight
4 months agoSalena
5 months agoEmmett
5 months agoVeronika
5 months agoCorinne
5 months ago