7 Types Of Security Data In Cybersecurity
The Snort rule that is triggered is:
alert ip any any -> any any (msg:"GPL ATTACK\_RESPONSE id check returned root"; content:"uid=0|28|root|29|"; fast\_pattern:only; classtype:bad-unknown; sid:2100498; rev:8;)
This rule generates an alert if any IP address in the network receives data from an external source that contains content with text matching the pattern of uid=0(root). The alert contains the message GPL ATTACK_RESPONSE id check returned root. The ID of the Snort rule that was triggered is 2100498.
The highlighted line in the figure displays a Sguil alert that was generated by visiting the testmyids website. The Snort rule and the packet data for the content received from the testmyvids webpage is displayed in the lower right-hand area of the Sguil interface.
Sguil Console Showing Test Alert from Snort IDS

Session and Transaction Data
Zeek Session Data – Partial Contents
Transaction Data
Full Packet Captures
The figure illustrates the interface for the Network Analysis Monitor component of the Cisco Prime Infrastructure system, which, like Wireshark, can display full packet captures.
Cisco Prime Network Analysis Module – Full Packet Capture
![The figure shows three main sections. The first section is a table with the following headings: No. time source destination protocol length info. The first line is highlighted with text: 38333 2.691104 1 dot 2 dot 0 dot 2 t c p 70 [t c p dup a c k 34839#1] [t c p ACKed unseen segment] 54735 > h t t p [a c k]. The second section has rows with row 1 text: frame 1:1504 bytes on wire (12032 bits), 1500 bytes captured (12000 bits). Second row: Ethernet II, src: 02:1a:c5:01:00:00 (02:1a:c5:01:00:00), dst: 02:1a:c5:02:00:00 (02:1a:c5:02:00:00). Row 3 text: internet protocol version 4 src: 1 dot 2 dot 0 dot 2 (1 dot 2 dot 0 dot 2) dst: 1 dot 3 dot 1 dot 229 (1 dot 3 dot 1 dot 229). Row 4 text: transmission control protocol, src port: h t t p (80), d s t port: 55998 (55998) seq:1, a c k: 1 len: 1438. Row 5 hypertext tractor protocol. The bottom section is hexadecimal and ascii text lines. An example from the first line: 0000 02 1a c5 02 00 00 02 1a c5 01 00 00 08 00 45 00 .............E.](https://i0.wp.com/contenthub.netacad.com/courses/cyberops/bc163a40-c2f9-11ea-a9a7-45d8616d4f83/bc180f00-c2f9-11ea-a9a7-45d8616d4f83/assets/5b0e6500-c6e2-11ea-9b13-039d6a7cea05.png?w=1170&ssl=1)
Statistical Data
An example of an NSM tool that utilizes statistical analysis is Cisco Cognitive Threat Analytics. It is able to find a malicious activity that has bypassed security controls or entered the network through unmonitored channels (including removable media) and is operating inside an organization’s environment.
PS: If you would like to have an online course on any of the courses that you found on this blog, I will be glad to do that on an individual and corporate level, I will be very glad to do that I have trained several individuals and groups and they are doing well in their various fields of endeavour. Some of those that I have trained includes staffs of Dangote Refinery, FCMB, Zenith Bank, New Horizons Nigeria among others. Please come on Whatsapp and let’s talk about your training. You can reach me on Whatsapp HERE. Please note that I will be using Microsoft Team to facilitate the training.
I know you might agree with some of the points that I have raised in this article. You might not agree with some of the issues raised. Let me know your views about the topic discussed. We will appreciate it if you can drop your comment. Thanks in anticipation.
Fact Check Policy
CRMNAIJA is committed to fact-checking in a fair, transparent and non-partisan manner. Therefore, if you’ve found an error in any of our reports, be it factual, editorial, or an outdated post, please contact us to tell us about it.
|