Skip to main content

Network traffic analysis

The PiRogue analyzes, continuously and automatically, the network traffic of every device connected to it. You do not have to start anything: the results appear in the dashboard within minutes.

Two complementary techniques are used:

TechniqueToolWhat it tells you
Deep Packet InspectionNFStreamWho talks to whom: which application, which server, how much data
Rule-based threat detectionSuricataIs it known to be malicious? Raises an alert when the traffic matches a known threat

Deep Packet Inspection​

DPI looks beyond the addresses of a packet. For every network flow, NFStream determines the source and destination, the ports, the protocol, the application involved (even when the traffic is encrypted with TLS) and the domain name of the server. This makes patterns and anomalies visible: an unknown app contacting a server in a country you did not expect, an unusual volume of data sent at night…

Threat detection​

An intrusion detection system (IDS) compares the traffic against a database of known threats, called signatures or rules, and raises an alert on a match. Suricata is the IDS of the PiRogue. It runs in passive mode: it observes and reports, it never blocks traffic.

The PiRogue comes with rules from ProofPoint Emerging Threats Open and Echap, refreshed every day.

No alert does not mean no threat

Suricata only detects threats that are already known. An empty alert list does not prove a device is clean: use the flows in the dashboard and the captured traffic to look for the unexpected.

Keep the RAM in mind

Suricata needs memory to hold its rules. It is automatically disabled on devices with less than 2.5 GB of RAM.

Where to look next​