Boost Application Experience with Flowmon Network Behaviour Analysis
Defending networks, systems, data, and people from cyberattacks is complex and requires a multifaceted strategy. In addition to the traditional security solutions we all know, like firewalls, detection intrusion systems, and anti-malware/anti-virus solutions, there is a need for intelligent monitoring of activity on networks. This needs to be able to highlight anomalies and is increasingly seen as a core part of a multi-layered defence strategy. This is what a network behaviour analysis (NBA) solution does, and Progress Flowmon Anomaly Detection System (ADS) delivers it in an easy-to-use yet powerful solution.
What is Network Behaviour Analysis?
Network behaviour analysis tools learn typical network activity patterns over time and scan behaviour to spot anomalies or deviations from the norm. An NBA solution should deliver these five core features:
- Continuous network monitoring - Cyberattacks occur 24x7, so monitoring and response must be 24x7 to be effective. It also means that the ADS needs to know about differing network traffic behaviour patterns throughout the day. It shouldn’t rely on signatures alone to spot unusual activity, but instead, it should dynamically learn the network and spot deviations from the norm.
- Analysis of encrypted traffic - Organisations should encrypt all data in transit over a network. The NBA solution must be able to decrypt traffic to inspect packet flows to check for risk indicators. And it should perform this task without any performance overhead.
- Detailed awareness of network behaviour - Simply reporting any abnormal behaviour detected isn’t enough. The NBA solution needs to have knowledge of threats to classify them while reporting details to cybersecurity teams. Flowmon ADS uses the MITRE ATT&CK Framework to classify detected threats and anomalies, the likely threat vector, and what mitigation responses are applicable in a human-understandable form.
- Real-time alerts - Rapid response is vital to counter cyberattacks. This is especially true for attacks like ransomware that look to spread and encrypt many network devices in rapid time. Getting prompt notification of abnormal activity on the network allows infected systems to be isolated and stops infections from spreading.
- Built-in response tools or connections to external response solutions - The need to trigger rapid responses leads on from rapid alerting. The NBA solution should have built-in response mechanisms, or should it integrate with third-party NDR or SIEM systems to allow quick responses to stop emerging attacks.
In addition to the above, NBA is critical for root cause analysis to identify how attackers breached systems so that gaps can be closed to prevent use in the future. Gartner analysts see NBA and anomaly detection as fundamental to defence-in-depth protection as it bridges the gap between endpoint devices and perimeter protection by residing within the network monitoring activity.
Flowmon ADS Delivers NBA You Can Use
Flowmon ADS is a core component of the Flowmon toolset. It delivers network behaviour analysis, automatic detection of security and operational issues, and network anomaly detection. ADS uses an intelligent detection engine and behaviour analysis algorithms to detect anomalies concealed within network traffic. The AI-based algorithms expose malicious behaviours, attacks against mission-critical applications, data breaches, and many other indicators of compromise like those outlined in the Mitre ATT&CK framework.
It works with NetFlow/IPFIX traffic monitoring and can do full packet capture when required. Organisations can map normal traffic behaviours over time, and any deviations from this regular traffic get flagged as an anomaly. The intelligence built into Flowmon’s solutions filters out noise in the signal to reduce false positives. This reduces the time cybersecurity teams need to spend analysing events that are not a threat and gives them more time to focus on real issues.
The Flowmon ADS Network anomaly detection system page provides a comprehensive overview of the solution and the technologies it uses.
Find Out More
You can read a deeper dive into boosting application experience with Flowmon ADS in this recent Flowmon Blog article.
To talk to someone about how deploying Flowmon ADS can improve the application experience and security of your networks, or those of your MSP clients, reach out to your Renaissance contact or use this form to arrange a chat with someone about Flowmon ADS and how you can integrate it into your environment.

