Sensor deployment types

We just looked at uniflow and bitflow. Let's discuss the FRP deployment and architectures followed for smooth network analysis. Generally, the FRP components are connected to a network in the setup shown in the following diagram:

The preceding diagram highlights the sensor deployment in a network where the sensor is a part of the router, and through a dedicated channel, it transports logs to the collector from where they are stored to the storage units. The storage units are further connected to the analyzer for in-depth analysis. The architecture can vary from one type to another, such as for host-flow, perimeter, ...

Get Hands-On Network Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.