Skip to main content 홈 크리에이터 autohandai community-skills implementing-ot-network-traffic-analysis-with-nozomi
implementing-ot-network-traffic-analysis-with-nozomi Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.
설치로 이동 Skills Marketplace 커뮤니티가 만든 AI 스킬을 발견하고 탐색하세요.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/autohandai/community-skills --skill implementing-ot-network-traffic-analysis-with-nozomi명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
Zip 다운로드 다운로드 중... name implementing-ot-network-traffic-analysis-with-nozomi description Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.
domain cybersecurity subdomain ot-ics-security tags ["ot-security","ics","nozomi","guardian","network-monitoring","asset-visibility","anomaly-detection","ndr"] version 1.0 author mahipal license Apache-2.0
Implementing OT Network Traffic Analysis with Nozomi
When to Use
When deploying passive OT network monitoring using Nozomi Networks Guardian sensors
When requiring asset visibility without active scanning in sensitive ICS environments
When building a Nozomi-based OT SOC with centralized management via Vantage or CMC
When integrating OT network monitoring with Fortinet, Splunk, or ServiceNow ecosystems
When monitoring compliance with IEC 62443 network segmentation policies
Do not use for active vulnerability scanning of OT devices (see performing-ot-vulnerability-scanning-safely), for environments standardized on Dragos (see implementing-dragos-platform-for-ot-monitoring), or for IT-only network monitoring.
Prerequisites
Nozomi Networks Guardian sensor (hardware, VM, or container)
Network TAP or SPAN port configured on monitored OT network segments
Nozomi Vantage (cloud) or Central Management Console for multi-sensor management
Nozomi Threat Intelligence subscription for updated detection signatures
Network architecture documentation for sensor placement planning
Workflow
Step 1: Deploy Guardian Sensors for Passive Monitoring
"""Nozomi Guardian Deployment Manager and Alert Analyzer.
Manages Nozomi Guardian sensor deployment validation, asset inventory
extraction, and threat alert analysis for OT environments.
"""
import json
import sys
from collections import defaultdict
from datetime import datetime
from typing import Dict , List , Optional
try :
import requests
except ImportError:
print ("Install requests: pip install requests" )
sys.exit(1 )
class NozomiGuardianManager :
"""Manages Nozomi Networks Guardian for OT monitoring."""
( ):
.guardian_url = guardian_url.rstrip( )
.session = requests.Session()
.session.headers.update({
: ,
: ,
})
.session.verify = verify_ssl
( ) -> [ ]:
params = {}
node_type:
params[ ] = node_type
resp = .session.get( , params=params)
resp.raise_for_status()
resp.json().get( , [])
( ) -> [ ]:
params = { : severity, : limit, : }
resp = .session.get( , params=params)
resp.raise_for_status()
resp.json().get( , [])
( ) -> [ ]:
resp = .session.get( )
resp.raise_for_status()
resp.json().get( , [])
( ) -> [ ]:
resp = .session.get( )
resp.raise_for_status()
resp.json().get( , [])
( ):
( )
( )
( )
( )
( )
:
resp = .session.get( )
resp.status_code == :
status = resp.json()
( )
( )
( )
( )
( )
requests.RequestException e:
( )
nodes = .get_nodes()
( )
( )
type_counts = defaultdict( )
vendor_counts = defaultdict( )
protocol_set = ()
node nodes:
type_counts[node.get( , )] +=
vendor_counts[node.get( , )] +=
proto node.get( , []):
protocol_set.add(proto)
( )
ntype, count (type_counts.items(), key= x: -x[ ]):
( )
( )
vendor, count (vendor_counts.items(), key= x: -x[ ])[: ]:
( )
( )
alerts = .get_alerts(severity= )
( )
( )
alert_types = defaultdict( )
alert alerts:
alert_types[alert.get( , )] +=
atype, count (alert_types.items(), key= x: -x[ ])[: ]:
( )
vulns = .get_vulnerabilities()
( )
( )
sev_counts = defaultdict( )
vuln vulns:
sev_counts[vuln.get( , )] +=
sev [ , , , ]:
sev sev_counts:
( )
( ):
links = .get_links()
nodes = {n.get( ): n n .get_nodes()}
( )
( )
cross_zone = []
link links:
src_node = nodes.get(link.get( ), {})
dst_node = nodes.get(link.get( ), {})
src_zone = src_node.get( , )
dst_zone = dst_node.get( , )
src_zone != dst_zone src_zone != dst_zone != :
cross_zone.append({
: src_node.get( , ),
: src_zone,
: dst_node.get( , ),
: dst_zone,
: link.get( , []),
})
cross_zone:
( )
comm cross_zone[: ]:
(
)
__name__ == :
manager = NozomiGuardianManager(
guardian_url= ,
api_token= ,
)
manager.validate_deployment()
manager.analyze_communication_patterns()
def
__init__
self, guardian_url: str , api_token: str , verify_ssl: bool = False
self
"/"
self
self
"Authorization"
f"Bearer {api_token} "
"Content-Type"
"application/json"
self
def
get_nodes
self, node_type: Optional [str ] = None
List
Dict
"""Retrieve discovered network nodes (assets)."""
if
"type"
self
f"{self.guardian_url} /api/v1/nodes"
return
"result"
def
get_alerts
self, severity: str = "high" , limit: int = 100
List
Dict
"""Retrieve security alerts."""
"severity"
"limit"
"status"
"open"
self
f"{self.guardian_url} /api/v1/alerts"
return
"result"
def
get_links
self
List
Dict
"""Retrieve communication links between nodes."""
self
f"{self.guardian_url} /api/v1/links"
return
"result"
def
get_vulnerabilities
self
List
Dict
"""Retrieve detected vulnerabilities."""
self
f"{self.guardian_url} /api/v1/vulnerabilities"
return
"result"
def
validate_deployment
self
"""Validate Guardian sensor deployment and coverage."""
print
f"\n{'=' *65 } "
print
"NOZOMI GUARDIAN DEPLOYMENT VALIDATION"
print
f"{'=' *65 } "
print
f"Guardian URL: {self.guardian_url} "
print
f"Validation Time: {datetime.now().isoformat()} "
try
self
f"{self.guardian_url} /api/v1/system/status"
if
200
print
f"\n--- SYSTEM STATUS ---"
print
f" Version: {status.get('version' , 'N/A' )} "
print
f" Uptime: {status.get('uptime' , 'N/A' )} "
print
f" Packets Processed: {status.get('packets_processed' , 'N/A' )} "
print
f" Threat Intelligence: {status.get('threat_intelligence_version' , 'N/A' )} "
except
as
print
f" [!] System status unavailable: {e} "
self
print
f"\n--- ASSET DISCOVERY ---"
print
f" Total Nodes Discovered: {len (nodes)} "
int
int
set
for
in
"type"
"unknown"
1
"vendor"
"Unknown"
1
for
in
"protocols"
print
f"\n By Type:"
for
in
sorted
lambda
1
print
f" {ntype} : {count} "
print
f"\n By Vendor:"
for
in
sorted
lambda
1
10
print
f" {vendor} : {count} "
print
f"\n Protocols Observed: {', ' .join(sorted (protocol_set))} "
self
"high"
print
f"\n--- ALERT SUMMARY ---"
print
f" High/Critical Alerts: {len (alerts)} "
int
for
in
"type_id"
"unknown"
1
for
in
sorted
lambda
1
10
print
f" {atype} : {count} "
self
print
f"\n--- VULNERABILITY SUMMARY ---"
print
f" Total Vulnerabilities: {len (vulns)} "
int
for
in
"severity"
"unknown"
1
for
in
"critical"
"high"
"medium"
"low"
if
in
print
f" {sev.capitalize()} : {sev_counts[sev]} "
def
analyze_communication_patterns
self
"""Analyze OT communication patterns for anomalies."""
self
"id"
for
in
self
print
f"\n--- COMMUNICATION ANALYSIS ---"
print
f" Total Communication Links: {len (links)} "
for
in
"source_id"
"destination_id"
"zone"
"unknown"
"zone"
"unknown"
if
and
"unknown"
and
"unknown"
"source"
"label"
"Unknown"
"source_zone"
"destination"
"label"
"Unknown"
"dest_zone"
"protocols"
"protocols"
if
print
f"\n Cross-Zone Communications: {len (cross_zone)} "
for
in
10
print
f" {comm['source' ]} ({comm['source_zone' ]} ) -> "
f"{comm['destination' ]} ({comm['dest_zone' ]} ) "
f"via {', ' .join(comm['protocols' ])} "
if
"__main__"
"https://nozomi-guardian.plant.local"
"your-api-token"
Key Concepts Term Definition Guardian Nozomi Networks passive sensor that monitors OT network traffic via SPAN/TAP without generating additional traffic Vantage Nozomi cloud-based central management platform for aggregating data across multiple Guardian sensors Behavioral Anomaly Detection (BAD) Nozomi's AI-driven approach to detecting deviations from learned normal OT network behavior Smart Polling Nozomi's active query feature using native protocols to safely extract additional device details Asset Intelligence Nozomi's automatic identification and classification of OT/IoT assets from network traffic Threat Intelligence Feed Nozomi Labs-maintained feed of OT-specific threat indicators, updated based on global honeypot data
Output Format NOZOMI GUARDIAN OT MONITORING REPORT
=======================================
Site: [site name]
Date: YYYY-MM-DD
ASSET VISIBILITY:
Total Assets: [count]
PLCs: [count] | HMIs: [count] | Switches: [count]
Protocols: [list]
Vendors: [top 5]
THREAT DETECTION:
Critical Alerts: [count]
High Alerts: [count]
Top Alert Categories: [list]
VULNERABILITIES:
Critical: [count]
High: [count]
NETWORK ANALYSIS:
Communication Links: [count]
Cross-Zone Flows: [count]