When you monitor internal traffic in your organization, the following things should be checked:
- Traffic that is generated from known addresses (in the organization):
- Normal: This is the traffic from known addresses and address ranges
- Suspicious: This is the traffic from/to addresses that you don't know
- Applications and port numbers:
- Normal: This includes standard port numbers, 80 (HTTP), 137/8/9 (NetBIOS), 3389 (RDP), 20/21 (FTP), 25110 (Mail), 53 (DNS), and so on. Be sure of the applications that run over the network, and verify that these are the only port numbers that you see.
- Suspicious: This includes unusual port numbers, that is, port numbers that do not belong to applications that run on server (for example, RDP ...