Skip to main content Início Criadores autohandai community-skills implementing-ot-network-traffic-analysis-with-nozomi
implementing-ot-network-traffic-analysis-with-nozomi Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.
Ir para a instalação Skills Marketplace Descubra e explore skills de IA criadas pela comunidade.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Copiar promptMostrar detalhes do prompt Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
npx skills add https://github.com/autohandai/community-skills --skill implementing-ot-network-traffic-analysis-with-nozomiO comando permanece em uma só linha. Role horizontalmente para revisá-lo antes de copiar.
Prefere uma cópia local? Baixe os arquivos disponíveis atualmente no SkillsMP.
Baixar Zip Baixando... Ocupações relacionadas SOC
Baseado na classificação ocupacional SOC
Explorador de arquivos
4 arquivos name implementing-ot-network-traffic-analysis-with-nozomi description Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.
domain cybersecurity subdomain ot-ics-security tags ["ot-security","ics","nozomi","guardian","network-monitoring","asset-visibility","anomaly-detection","ndr"] version 1.0 author mahipal license Apache-2.0
Implementing OT Network Traffic Analysis with Nozomi
When to Use
When deploying passive OT network monitoring using Nozomi Networks Guardian sensors
When requiring asset visibility without active scanning in sensitive ICS environments
When building a Nozomi-based OT SOC with centralized management via Vantage or CMC
When integrating OT network monitoring with Fortinet, Splunk, or ServiceNow ecosystems
When monitoring compliance with IEC 62443 network segmentation policies
Do not use for active vulnerability scanning of OT devices (see performing-ot-vulnerability-scanning-safely), for environments standardized on Dragos (see implementing-dragos-platform-for-ot-monitoring), or for IT-only network monitoring.
Prerequisites
Nozomi Networks Guardian sensor (hardware, VM, or container)
Network TAP or SPAN port configured on monitored OT network segments
Nozomi Vantage (cloud) or Central Management Console for multi-sensor management
Nozomi Threat Intelligence subscription for updated detection signatures
Network architecture documentation for sensor placement planning
Workflow
Step 1: Deploy Guardian Sensors for Passive Monitoring
"""Nozomi Guardian Deployment Manager and Alert Analyzer.
Manages Nozomi Guardian sensor deployment validation, asset inventory
extraction, and threat alert analysis for OT environments.
"""
import json
import sys
from collections import defaultdict
from datetime import datetime
from typing import Dict , List , Optional
try :
import requests
except ImportError:
print ("Install requests: pip install requests" )
sys.exit(1 )
class NozomiGuardianManager :
"""Manages Nozomi Networks Guardian for OT monitoring."""
( ):
.guardian_url = guardian_url.rstrip( )
.session = requests.Session()
.session.headers.update({
: ,
: ,
})
.session.verify = verify_ssl
( ) -> [ ]:
params = {}
node_type:
params[ ] = node_type
resp = .session.get( , params=params)
resp.raise_for_status()
resp.json().get( , [])
( ) -> [ ]:
params = { : severity, : limit, : }
resp = .session.get( , params=params)
resp.raise_for_status()
resp.json().get( , [])
( ) -> [ ]:
resp = .session.get( )
resp.raise_for_status()
resp.json().get( , [])
( ) -> [ ]:
resp = .session.get( )
resp.raise_for_status()
resp.json().get( , [])
( ):
( )
( )
( )
( )
( )
:
resp = .session.get( )
resp.status_code == :
status = resp.json()
( )
( )
( )
( )
( )
requests.RequestException e:
( )
nodes = .get_nodes()
( )
( )
type_counts = defaultdict( )
vendor_counts = defaultdict( )
protocol_set = ()
node nodes:
type_counts[node.get( , )] +=
vendor_counts[node.get( , )] +=
proto node.get( , []):
protocol_set.add(proto)
( )
ntype, count (type_counts.items(), key= x: -x[ ]):
( )
( )
vendor, count (vendor_counts.items(), key= x: -x[ ])[: ]:
( )
( )
alerts = .get_alerts(severity= )
( )
( )
alert_types = defaultdict( )
alert alerts:
alert_types[alert.get( , )] +=
atype, count (alert_types.items(), key= x: -x[ ])[: ]:
( )
vulns = .get_vulnerabilities()
( )
( )
sev_counts = defaultdict( )
vuln vulns:
sev_counts[vuln.get( , )] +=
sev [ , , , ]:
sev sev_counts:
( )
( ):
links = .get_links()
nodes = {n.get( ): n n .get_nodes()}
( )
( )
cross_zone = []
link links:
src_node = nodes.get(link.get( ), {})
dst_node = nodes.get(link.get( ), {})
src_zone = src_node.get( , )
dst_zone = dst_node.get( , )
src_zone != dst_zone src_zone != dst_zone != :
cross_zone.append({
: src_node.get( , ),
: src_zone,
: dst_node.get( , ),
: dst_zone,
: link.get( , []),
})
cross_zone:
( )
comm cross_zone[: ]:
(
)
__name__ == :
manager = NozomiGuardianManager(
guardian_url= ,
api_token= ,
)
manager.validate_deployment()
manager.analyze_communication_patterns()
def
__init__
self, guardian_url: str , api_token: str , verify_ssl: bool = False
self
"/"
self
self
"Authorization"
f"Bearer {api_token} "
"Content-Type"
"application/json"
self
def
get_nodes
self, node_type: Optional [str ] = None
List
Dict
"""Retrieve discovered network nodes (assets)."""
if
"type"
self
f"{self.guardian_url} /api/v1/nodes"
return
"result"
def
get_alerts
self, severity: str = "high" , limit: int = 100
List
Dict
"""Retrieve security alerts."""
"severity"
"limit"
"status"
"open"
self
f"{self.guardian_url} /api/v1/alerts"
return
"result"
def
get_links
self
List
Dict
"""Retrieve communication links between nodes."""
self
f"{self.guardian_url} /api/v1/links"
return
"result"
def
get_vulnerabilities
self
List
Dict
"""Retrieve detected vulnerabilities."""
self
f"{self.guardian_url} /api/v1/vulnerabilities"
return
"result"
def
validate_deployment
self
"""Validate Guardian sensor deployment and coverage."""
print
f"\n{'=' *65 } "
print
"NOZOMI GUARDIAN DEPLOYMENT VALIDATION"
print
f"{'=' *65 } "
print
f"Guardian URL: {self.guardian_url} "
print
f"Validation Time: {datetime.now().isoformat()} "
try
self
f"{self.guardian_url} /api/v1/system/status"
if
200
print
f"\n--- SYSTEM STATUS ---"
print
f" Version: {status.get('version' , 'N/A' )} "
print
f" Uptime: {status.get('uptime' , 'N/A' )} "
print
f" Packets Processed: {status.get('packets_processed' , 'N/A' )} "
print
f" Threat Intelligence: {status.get('threat_intelligence_version' , 'N/A' )} "
except
as
print
f" [!] System status unavailable: {e} "
self
print
f"\n--- ASSET DISCOVERY ---"
print
f" Total Nodes Discovered: {len (nodes)} "
int
int
set
for
in
"type"
"unknown"
1
"vendor"
"Unknown"
1
for
in
"protocols"
print
f"\n By Type:"
for
in
sorted
lambda
1
print
f" {ntype} : {count} "
print
f"\n By Vendor:"
for
in
sorted
lambda
1
10
print
f" {vendor} : {count} "
print
f"\n Protocols Observed: {', ' .join(sorted (protocol_set))} "
self
"high"
print
f"\n--- ALERT SUMMARY ---"
print
f" High/Critical Alerts: {len (alerts)} "
int
for
in
"type_id"
"unknown"
1
for
in
sorted
lambda
1
10
print
f" {atype} : {count} "
self
print
f"\n--- VULNERABILITY SUMMARY ---"
print
f" Total Vulnerabilities: {len (vulns)} "
int
for
in
"severity"
"unknown"
1
for
in
"critical"
"high"
"medium"
"low"
if
in
print
f" {sev.capitalize()} : {sev_counts[sev]} "
def
analyze_communication_patterns
self
"""Analyze OT communication patterns for anomalies."""
self
"id"
for
in
self
print
f"\n--- COMMUNICATION ANALYSIS ---"
print
f" Total Communication Links: {len (links)} "
for
in
"source_id"
"destination_id"
"zone"
"unknown"
"zone"
"unknown"
if
and
"unknown"
and
"unknown"
"source"
"label"
"Unknown"
"source_zone"
"destination"
"label"
"Unknown"
"dest_zone"
"protocols"
"protocols"
if
print
f"\n Cross-Zone Communications: {len (cross_zone)} "
for
in
10
print
f" {comm['source' ]} ({comm['source_zone' ]} ) -> "
f"{comm['destination' ]} ({comm['dest_zone' ]} ) "
f"via {', ' .join(comm['protocols' ])} "
if
"__main__"
"https://nozomi-guardian.plant.local"
"your-api-token"
Key Concepts Term Definition Guardian Nozomi Networks passive sensor that monitors OT network traffic via SPAN/TAP without generating additional traffic Vantage Nozomi cloud-based central management platform for aggregating data across multiple Guardian sensors Behavioral Anomaly Detection (BAD) Nozomi's AI-driven approach to detecting deviations from learned normal OT network behavior Smart Polling Nozomi's active query feature using native protocols to safely extract additional device details Asset Intelligence Nozomi's automatic identification and classification of OT/IoT assets from network traffic Threat Intelligence Feed Nozomi Labs-maintained feed of OT-specific threat indicators, updated based on global honeypot data
Output Format NOZOMI GUARDIAN OT MONITORING REPORT
=======================================
Site: [site name]
Date: YYYY-MM-DD
ASSET VISIBILITY:
Total Assets: [count]
PLCs: [count] | HMIs: [count] | Switches: [count]
Protocols: [list]
Vendors: [top 5]
THREAT DETECTION:
Critical Alerts: [count]
High Alerts: [count]
Top Alert Categories: [list]
VULNERABILITIES:
Critical: [count]
High: [count]
NETWORK ANALYSIS:
Communication Links: [count]
Cross-Zone Flows: [count]