Glossary
/
OT Security Concepts

Passive Network Monitoring

Also known as:
Passive monitoring · out-of-band monitoring · traffic mirroring

Passive network monitoring analyzes a copy of network traffic, obtained through a SPAN (mirror) port or a network TAP, without injecting any packets into the monitored network. It is the default approach for safety-critical rail systems because it cannot interfere with operations.

How it works

A switch is configured to mirror traffic from selected ports or VLANs to a monitoring port, or a hardware TAP is inserted inline to copy traffic optically or electrically. A sensor connected to that copy parses the protocols, identifies devices and their communication relationships, and detects anomalies. Nothing is sent back into the operational network.

Where passive visibility is insufficient, for example to read firmware versions, carefully scoped active polling (such as SNMP queries) may complement it, but this is the exception rather than the default.

Why it matters for security

Safety-certified signaling systems cannot tolerate unplanned traffic, and active scanning has caused outages in OT environments. Passive monitoring delivers asset inventory, segmentation validation and threat detection with zero operational impact, which is why it is the accepted baseline for rail OT security.

Related solution

Vulnerability assessment in safety-critical rail environments

Assessing exposure without active scanning of certified systems.

See the solution →

Related terms

Ready to protect your rail?

Our specialists will help you back on track

Talk with an Expert