
Comparison of Traditional Networking and SDN for Anomaly Detection
networkingSDNanomaly_detectioncybersecuritytraffic_captureSPANmirror_ports
The post compares two approaches for network traffic capture in anomaly detection: industry methods (using SPAN/mirror ports with dedicated appliances like Nozomi or Garland) and research-focused SDN (which provides a centralized view of flows without extra hardware). The author questions why SDN isn’t widely adopted in commercial anomaly detection solutions, suggesting potential reasons like deployment cost, compatibility, performance, or security concerns. They seek insights from professionals with real-world networking or cybersecurity experience.