Skip to main content 首页 创作者 autohandai community-skills implementing-ot-network-traffic-analysis-with-nozomi
implementing-ot-network-traffic-analysis-with-nozomi Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.
跳到安装 Skills Marketplace 发现并探索由社区构建的 Agent Skills
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/autohandai/community-skills --skill implementing-ot-network-traffic-analysis-with-nozomi命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
下载 Zip 下载中... name implementing-ot-network-traffic-analysis-with-nozomi description Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.
domain cybersecurity subdomain ot-ics-security tags ["ot-security","ics","nozomi","guardian","network-monitoring","asset-visibility","anomaly-detection","ndr"] version 1.0 author mahipal license Apache-2.0
Implementing OT Network Traffic Analysis with Nozomi
When to Use
When deploying passive OT network monitoring using Nozomi Networks Guardian sensors
When requiring asset visibility without active scanning in sensitive ICS environments
When building a Nozomi-based OT SOC with centralized management via Vantage or CMC
When integrating OT network monitoring with Fortinet, Splunk, or ServiceNow ecosystems
When monitoring compliance with IEC 62443 network segmentation policies
Do not use for active vulnerability scanning of OT devices (see performing-ot-vulnerability-scanning-safely), for environments standardized on Dragos (see implementing-dragos-platform-for-ot-monitoring), or for IT-only network monitoring.
Prerequisites
Nozomi Networks Guardian sensor (hardware, VM, or container)
Network TAP or SPAN port configured on monitored OT network segments
Nozomi Vantage (cloud) or Central Management Console for multi-sensor management
Nozomi Threat Intelligence subscription for updated detection signatures
Network architecture documentation for sensor placement planning
Workflow
Step 1: Deploy Guardian Sensors for Passive Monitoring
"""Nozomi Guardian Deployment Manager and Alert Analyzer.
Manages Nozomi Guardian sensor deployment validation, asset inventory
extraction, and threat alert analysis for OT environments.
"""
import json
import sys
from collections import defaultdict
from datetime import datetime
from typing import Dict , List , Optional
try :
import requests
except ImportError:
print ("Install requests: pip install requests" )
sys.exit(1 )
class NozomiGuardianManager :
"""Manages Nozomi Networks Guardian for OT monitoring."""
( ):
.guardian_url = guardian_url.rstrip( )
.session = requests.Session()
.session.headers.update({
: ,
: ,
})
.session.verify = verify_ssl
( ) -> [ ]:
params = {}
node_type:
params[ ] = node_type
resp = .session.get( , params=params)
resp.raise_for_status()
resp.json().get( , [])
( ) -> [ ]:
params = { : severity, : limit, : }
resp = .session.get( , params=params)
resp.raise_for_status()
resp.json().get( , [])
( ) -> [ ]:
resp = .session.get( )
resp.raise_for_status()
resp.json().get( , [])
( ) -> [ ]:
resp = .session.get( )
resp.raise_for_status()
resp.json().get( , [])
( ):
( )
( )
( )
( )
( )
:
resp = .session.get( )
resp.status_code == :
status = resp.json()
( )
( )
( )
( )
( )
requests.RequestException e:
( )
nodes = .get_nodes()
( )
( )
type_counts = defaultdict( )
vendor_counts = defaultdict( )
protocol_set = ()
node nodes:
type_counts[node.get( , )] +=
vendor_counts[node.get( , )] +=
proto node.get( , []):
protocol_set.add(proto)
( )
ntype, count (type_counts.items(), key= x: -x[ ]):
( )
( )
vendor, count (vendor_counts.items(), key= x: -x[ ])[: ]:
( )
( )
alerts = .get_alerts(severity= )
( )
( )
alert_types = defaultdict( )
alert alerts:
alert_types[alert.get( , )] +=
atype, count (alert_types.items(), key= x: -x[ ])[: ]:
( )
vulns = .get_vulnerabilities()
( )
( )
sev_counts = defaultdict( )
vuln vulns:
sev_counts[vuln.get( , )] +=
sev [ , , , ]:
sev sev_counts:
( )
( ):
links = .get_links()
nodes = {n.get( ): n n .get_nodes()}
( )
( )
cross_zone = []
link links:
src_node = nodes.get(link.get( ), {})
dst_node = nodes.get(link.get( ), {})
src_zone = src_node.get( , )
dst_zone = dst_node.get( , )
src_zone != dst_zone src_zone != dst_zone != :
cross_zone.append({
: src_node.get( , ),
: src_zone,
: dst_node.get( , ),
: dst_zone,
: link.get( , []),
})
cross_zone:
( )
comm cross_zone[: ]:
(
)
__name__ == :
manager = NozomiGuardianManager(
guardian_url= ,
api_token= ,
)
manager.validate_deployment()
manager.analyze_communication_patterns()
def
__init__
self, guardian_url: str , api_token: str , verify_ssl: bool = False
self
"/"
self
self
"Authorization"
f"Bearer {api_token} "
"Content-Type"
"application/json"
self
def
get_nodes
self, node_type: Optional [str ] = None
List
Dict
"""Retrieve discovered network nodes (assets)."""
if
"type"
self
f"{self.guardian_url} /api/v1/nodes"
return
"result"
def
get_alerts
self, severity: str = "high" , limit: int = 100
List
Dict
"""Retrieve security alerts."""
"severity"
"limit"
"status"
"open"
self
f"{self.guardian_url} /api/v1/alerts"
return
"result"
def
get_links
self
List
Dict
"""Retrieve communication links between nodes."""
self
f"{self.guardian_url} /api/v1/links"
return
"result"
def
get_vulnerabilities
self
List
Dict
"""Retrieve detected vulnerabilities."""
self
f"{self.guardian_url} /api/v1/vulnerabilities"
return
"result"
def
validate_deployment
self
"""Validate Guardian sensor deployment and coverage."""
print
f"\n{'=' *65 } "
print
"NOZOMI GUARDIAN DEPLOYMENT VALIDATION"
print
f"{'=' *65 } "
print
f"Guardian URL: {self.guardian_url} "
print
f"Validation Time: {datetime.now().isoformat()} "
try
self
f"{self.guardian_url} /api/v1/system/status"
if
200
print
f"\n--- SYSTEM STATUS ---"
print
f" Version: {status.get('version' , 'N/A' )} "
print
f" Uptime: {status.get('uptime' , 'N/A' )} "
print
f" Packets Processed: {status.get('packets_processed' , 'N/A' )} "
print
f" Threat Intelligence: {status.get('threat_intelligence_version' , 'N/A' )} "
except
as
print
f" [!] System status unavailable: {e} "
self
print
f"\n--- ASSET DISCOVERY ---"
print
f" Total Nodes Discovered: {len (nodes)} "
int
int
set
for
in
"type"
"unknown"
1
"vendor"
"Unknown"
1
for
in
"protocols"
print
f"\n By Type:"
for
in
sorted
lambda
1
print
f" {ntype} : {count} "
print
f"\n By Vendor:"
for
in
sorted
lambda
1
10
print
f" {vendor} : {count} "
print
f"\n Protocols Observed: {', ' .join(sorted (protocol_set))} "
self
"high"
print
f"\n--- ALERT SUMMARY ---"
print
f" High/Critical Alerts: {len (alerts)} "
int
for
in
"type_id"
"unknown"
1
for
in
sorted
lambda
1
10
print
f" {atype} : {count} "
self
print
f"\n--- VULNERABILITY SUMMARY ---"
print
f" Total Vulnerabilities: {len (vulns)} "
int
for
in
"severity"
"unknown"
1
for
in
"critical"
"high"
"medium"
"low"
if
in
print
f" {sev.capitalize()} : {sev_counts[sev]} "
def
analyze_communication_patterns
self
"""Analyze OT communication patterns for anomalies."""
self
"id"
for
in
self
print
f"\n--- COMMUNICATION ANALYSIS ---"
print
f" Total Communication Links: {len (links)} "
for
in
"source_id"
"destination_id"
"zone"
"unknown"
"zone"
"unknown"
if
and
"unknown"
and
"unknown"
"source"
"label"
"Unknown"
"source_zone"
"destination"
"label"
"Unknown"
"dest_zone"
"protocols"
"protocols"
if
print
f"\n Cross-Zone Communications: {len (cross_zone)} "
for
in
10
print
f" {comm['source' ]} ({comm['source_zone' ]} ) -> "
f"{comm['destination' ]} ({comm['dest_zone' ]} ) "
f"via {', ' .join(comm['protocols' ])} "
if
"__main__"
"https://nozomi-guardian.plant.local"
"your-api-token"
Key Concepts Term Definition Guardian Nozomi Networks passive sensor that monitors OT network traffic via SPAN/TAP without generating additional traffic Vantage Nozomi cloud-based central management platform for aggregating data across multiple Guardian sensors Behavioral Anomaly Detection (BAD) Nozomi's AI-driven approach to detecting deviations from learned normal OT network behavior Smart Polling Nozomi's active query feature using native protocols to safely extract additional device details Asset Intelligence Nozomi's automatic identification and classification of OT/IoT assets from network traffic Threat Intelligence Feed Nozomi Labs-maintained feed of OT-specific threat indicators, updated based on global honeypot data
Output Format NOZOMI GUARDIAN OT MONITORING REPORT
=======================================
Site: [site name]
Date: YYYY-MM-DD
ASSET VISIBILITY:
Total Assets: [count]
PLCs: [count] | HMIs: [count] | Switches: [count]
Protocols: [list]
Vendors: [top 5]
THREAT DETECTION:
Critical Alerts: [count]
High Alerts: [count]
Top Alert Categories: [list]
VULNERABILITIES:
Critical: [count]
High: [count]
NETWORK ANALYSIS:
Communication Links: [count]
Cross-Zone Flows: [count]