Network traffic analysis
The PiRogue analyzes, continuously and automatically, the network traffic of every device connected to it. You do not have to start anything: the results appear in the dashboard within minutes.
Two complementary techniques are used:
| Technique | Tool | What it tells you |
|---|---|---|
| Deep Packet Inspection | NFStream | Who talks to whom: which application, which server, how much data |
| Rule-based threat detection | Suricata | Is it known to be malicious? Raises an alert when the traffic matches a known threat |
Deep Packet Inspection
DPI looks beyond the addresses of a packet. For every network flow, NFStream determines the source and destination, the ports, the protocol, the application involved (even when the traffic is encrypted with TLS) and the domain name of the server. This makes patterns and anomalies visible: an unknown app contacting a server in a country you did not expect, an unusual volume of data sent at night…
Threat detection
An intrusion detection system (IDS) compares the traffic against a database of known threats, called signatures or rules, and raises an alert on a match. Suricata is the IDS of the PiRogue. It runs in passive mode: it observes and reports, it never blocks traffic.
The PiRogue comes with rules from ProofPoint Emerging Threats Open and Echap, refreshed every day.
Suricata only detects threats that are already known. An empty alert list does not prove a device is clean: use the flows in the dashboard and the captured traffic to look for the unexpected.
Suricata needs memory to hold its rules. It is automatically disabled on devices with less than 2.5 GB of RAM.
Where to look next
- See the results: Dashboard
- Record the traffic for later: Capture network traffic
- Understand an alert: Suricata rules
- Add your own detection: Add your own Suricata rules