NBA technologies have some significant limitations. They are
delayed in detecting attacks because of their data sources,
especially when they rely on flow data from routers and other
network devices. This data is often transferred to the NBA in
batches from every minute to a few times an hour. Attacks that
occur quickly may not be detected until they have already
disrupted or damaged systems. This delay can be avoided by
using sensors that do their own packet captures and analysis;
however, this is much more resource-intensive than analyzing
flow data. Also, a single sensor can analyze flow data from
many networks, while a single sensor can generally directly
monitor only a few networks at once. Therefore, to do direct
monitoring instead of using flow data, organizations might have
to purchase more powerful sensors and/or more sensors.