Skip to main content
Version: Version 8.0

Network Behavior Anomaly Detection (NBAD)

NBAD is a suite of application-layer and behavioral dashboards built into Trisul Network Analytics. It goes beyond raw traffic volume by providing deep visibility into how your network is being used like surfacing encrypted tunnels, peer-to-peer abuse, TCP health, HTTP activity, and protocol breakdowns in a single unified menu. The solution combines flow analytics, Layer 7 visibility, behavioral monitoring, traffic investigation, and alerting capabilities through a collection of Trisul Apps and dashboards.

NBAD Menu Overview

The NBAD menu is accessible from the left navigation sidebar. It groups the following dashboards:

DashboardWhat it shows
Layer 7 MetricsApplication-layer breakdown: top apps, SNIs, TLS Root CAs, DNS traffic
HTTP TrafficHTTP method, status code, content type, host, and URL-level visibility
IPv4 / IPv6 DashboardSide-by-side breakdown of IPv4 vs IPv6 host and application activity
TunnelsDetection of encapsulated and tunneled protocols
DDoS MetricsDDoS attack detection and analysis
P2P AnalyticsPeer-to-peer traffic: BitTorrent, Tor, Gnutella, eMule, and more
TCP AnalyzerTCP health metrics: latency, retransmissions, timeouts, poor-quality flows
Flow MapLive geographic map of network session flows
MITRE ATT&CKNetwork activity mapped to MITRE ATT&CK techniques
In this page: