Detecting attacks often depends on knowing what normal looks like. A baseline, in the monitoring sense, is a documented picture of normal behavior for a system, network or user: typical traffic volumes, login times, running processes, resource use and communication patterns. Once you have a baseline, anything that differs significantly is an anomaly worth examining.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.