Network and server profiling is used to establish normal traffic on a network and server and, therefore, to help identify incidents in action. Profiling also allows administrators to identify any potential future problems, such as a lack of redundancy, or bottlenecks in the system.
Profiling is a fundamental network security task. Knowing what normal is allows us to better identify what isn't normal, and sets us on the path to defeating a threat.
The following topics will be covered in this chapter:
- Network profiling
- Server profiling