SI-4(25) - System Monitoring | Optimize Network Traffic Analysis

Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.


ID: SI-4(25)
Enhancement of : SI-4

Space Segment Guidance

Integrating near-real-time threat intelligence lets the mission pivot fast when adversaries change tactics. The security operations center pushes new indicator sets, for example, malicious IP ranges spotted scanning deep-space networks, through a signed bulletin that the ground station relays during the next contact. The onboard monitor loads the indicators into memory and begins filtering or rate-limiting traffic that matches without waiting for a full flight build. Expired indicators age out automatically, keeping the ruleset lean for embedded resources.