Information Gathering Capabilities: NBA technologies offer
extensive information gathering capabilities, because knowledge
of the characteristics of the organization’s hosts is needed for
most of the NBA product’s detection techniques. NBA sensors
can automatically create and maintain lists of hosts
communicating on the organization’s monitored networks. They
can monitor port usage, perform passive fingerprinting, and use
other techniques to gather detailed information on the hosts.
Information typically collected for each host includes the
following: IP address, operating system, what services it is
providing, including the IP protocols and TCP and UDP ports it
uses to do so, other hosts with which it communicates, and what
services it uses and which IP protocols and TCP or UDP ports it
contacts on each host. NBA sensors constantly monitor network
activity for changes to this information.