How NTA Works
What does an NTA solution do?
NTA solutions continuously analyze network telemetry and/or flow records (like NetFlow). They use a combination of machine learning and behavioral analytics to generate a baseline that reflects what normal network behavior looks like for the organization. When abnormal traffic patterns or irregular network activities are detected, these tools alert your security team to the potential threat.
In addition to monitoring north-south traffic that crosses the enterprise perimeter, NTA solutions monitor east-west communications by analyzing network traffic or flow records.
Why do you need an NTA solution?
NTA solutions can analyze all the entities or devices that make up your network—whether they are managed or unmanaged. NTA solutions ingest telemetry from multiple network devices like routers, switches, and firewalls to determine what "normal" behavior for these devices looks like and how parts of your network are being accessed and by whom.
Everything touches the network, so this visibility extends all the way from headquarters to branch offices, data centers, roaming users, and smart devices. Whether you are on-premises, in the cloud, or some combination, NTA solutions can give you much needed visibility and context into what is happening on your network.
How does NTA improve your security?
Once an NTA solution determines what normal behavior on your network looks like, it can alert your organization when anomalous behavior occurs. By alerting your security team to suspicious activity early on—whether the threat is coming from outside or inside your network—NTA solutions can provide the extended visibility you need to mitigate the security incident.
Network traffic analysis can attribute the malicious behavior to a specific IP and also perform forensic analysis to determine how the threat has moved laterally within the organization—and allow you to see what other devices might be infected. This leads to faster response in order to prevent any business impact.