Network Behaviour Analysis is promptly becoming a powerful tool for recognizing security incidents and intrusions in a network. A huge majority of malicious applications such as viruses, spyware, and botnet activity are very tough to identify for traditional network security devices, but a network behavior analysis solution will be able to identify the change in behavior from infected hosts. Usually, a host that is infected will change the pattern for how sessions are set up, the volume of sessions, may communicate to new ports or send data-traffic which is different to a non-infected host. Based on several characteristics a network behavior analysis solution will be able to flag or recognize suspicious traffic before any other security solutions such as antivirus or IPS systems may even have a signature for the infection.