|
|
|
|
|
by sofixa
1977 days ago
|
|
> Sec/ops doesn't normally involve looking at live network capture snapshots all day. ("Eyes on glass" monitoring exists, but that's not for common services) You're not distracting people from spotting exfil No, but if the people on call are being drowned in alerts because everything is down due to the DDoS, an alert saying there's anomalous traffic ( if it's even capable to detect that during a DDoS, when all traffic would be anomalous depending on infrastructure) could be easily missed. |
|
Volume is not the only way to notify about anomalies. Poisoned data entries / canaries, outbound traffic which should never exist, unexpected DNS queries, and many others will trigger regardless of DDoS.