Network Behavior Analysis (NBA) enables you to monitor an entire network. Normally, when monitoring a network for questionable behavior, one would need an Intrusion Detection or Prevention system (IPS) at each network segment. That is technically feasible, but, especially within large or multiple location networks, this is a costly solution.
Using Network Behavior Analysis, you can do without the Intrusion Detection or Prevention systems. NBA is especially worthwhile since it turns each switch or router in a network into a security device. That is, if this switch or router is able to produce sFlow based traffic statistics. This switch or router reports these statistics regularly to a central device. A central management console will subsequently correlate and interpret the statistics. Upon pinpointing suspicious traffic or when certain limits are exceeded, notifications will be sent to the administrator.
Applying NBA is a financially attractive option. You will easily gain a complete overview of your network security situation without having to engineer probes, IPS or inline systems.
Most switches and routers by Brocade, previously known as Foundry Networks, support sFlow technology. By using the management system IronView and Snort, the entire network can be closely monitored.