Server profiling is, again, used to create a picture of normal operation. While it is still broadly expected that server performance and operations will evolve over time, server profiles tend not to vary as rapidly or as markedly as network profiles.
In this section, we will look at five elements that are important to server profiling. Ports, related to the protocols connecting to them, is an obvious cross over between network and server metrics, but the other elements are more similar to those investigated in endpoint threat analyses.
Under the next five headings, we will look at each of these five elements independently. We will look at the technologies and processes that can be used to collect and monitor each data set, and some things that can be inferred from the elements, either in isolation or in combination.