Traditional networking vs SDN
I’m working on my final university project on network anomaly detection. The system analyzes network flows and generates alerts. While researching how enterprises capture network traffic, I noticed two approaches: Industry: SPAN/mirror ports with dedicated appliances (e.g. Nozomi, Garland) that sniff traffic and send features to an analytics server. Research: SDN, where the controller already has a centralized view of network flows, making monitoring seem much simpler without extra hardware. My question is: If SDN makes flow collection easier, why isn’t it widely used in commercial network anomaly detection solutions? Is it because of deployment cost, compatibility with existing networks, performance, security concerns, or something else? I’d appreciate insights from people with real-world networking or cybersecurity experience. submitted by /u/VEXX452 [link] [comments]Technical Information Security Content & DiscussionRead More