Network Intrusion Detection
Primary source needed
Public sources confirm that network logs feed security operations, but do not identify the current sensor products, placement, line rate or inspection design.
This node retains network intrusion detection as an architectural research lead. It does not currently attribute Zeek, Suricata or a particular border deployment to CERN.
Topology
- Part of: security-governance
- About: soc
- Cites: security-audited-for-the-better — confirms network-log ingestion, not the sensor implementation.
- Cites: revised-security-rules — contextual network-security governance.
