iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

Category: Network Visibility

( 11 Alerts)

Link became inactive

No traffic was detcted on the link for a period longer than 'Time Silent'. Time silent is automatically calculated during Learning mode.

Traffic Started on Network Interface

Traffic was re-detected on a interface.

Traffic Stopped on Network Interface

No tarffic was detected on the interface for a period of time greater than the 'Inactive range' that was defined as part of interface configuration.

Device re-detected

The system detected traffic on an inactive asset

Arp Poisoning

Multiple changes of the MAC address for a specific IP were detected in a short period of time - this pattern is typical for ARP poisioning attack attempt

Link re-detected

The system detected traffic on an inactive link

Device Became Inactive

A device that wasn't communicating recently and according to the iSID now is defined as inactive- can define in the isid the time frame of no communication in order to get as inactive.

New MAC Detected

A new Mac was learned for an existent device.

New Link Detected

link refers to source and destination and port. a new link will appear when a source and destination that haven't spoken before will speak for the first time

New Protocol Detected

new protocol that was discovered in an existing link (source and destination that already discovered in another protocol)