Police Cyber Alarm allows organisations to monitor malicious activity against their network. There are two aspects of the system, Firewall monitoring and vulnerability scanning.
Once the PCA Collector is installed it analyses data from the organisations firewall or other security devices such as Network Intrusion Detection/Prevention systems (IDS/IPS), Network Anti-Virus and Anti-Spam filters. It then compares the data to what has been detected by other PCA collectors to determine if an IP address is potentially acting maliciously.
Member organisations are then provided with reports, telling them which devices were targeted, the nature of any suspicious traffic, what port was accessed and if the traffic was blocked or allowed onto the network.
PCA is also able to scan an organisations web applications and external IP addresses automatically for known vulnerabilities and grades them on a scale of Critical, High, Medium and Low. The member is then provided with report detailing the nature of the vulnerability, the affected device, its severity and any relevant Common Vulnerabilities and Exposure code (CVE).
PCA only collects metadata and header information from the organisations system, it does not analyse the content of traffic or packets.