Tuning and Customization: NBA technologies rely primarily
on observing network traffic and developing baselines of
expected flows and inventories of host characteristics. NBA
products automatically update their baselines on an ongoing
basis. As a result, typically there is not much tuning or
customization to be done, other than updating firewall rule setlike
policies that are offered by most products. Also,
administrators might adjust thresholds periodically (e.g., how
much additional bandwidth usage should trigger an alert) to take
into account changes to the environment. Thresholds can often
be set on a per-host basis or for administrator-defined groups of
hosts. Most NBA products also offer white list and blacklist
capabilities for hosts and services. Another common feature of
NBA products is customization of each alert (e.g., specifying
which prevention option it should trigger). Unlike networkbased
IDPSs, code editing features are generally not applicable
to NBA products.