NetFlow use cases
ICmyNet / NetVizura
Miloš Zeković,
milos.zekovic@soneco.rs ICmyNet Chief Customer Officer Soneco d.o.o. Serbia
NetFlow use cases ICmyNet / NetVizura Milo Zekovi, - - PowerPoint PPT Presentation
NetFlow use cases ICmyNet / NetVizura Milo Zekovi, milos.zekovic@soneco.rs ICmyNet Chief Customer Officer Soneco d.o.o. Serbia Agenda ICmyNet / NetVizura overview Use cases / case studies Statistics per exporter/interfaces Traffic
Miloš Zeković,
milos.zekovic@soneco.rs ICmyNet Chief Customer Officer Soneco d.o.o. Serbia
2 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
Statistics per exporter/interfaces Traffic Patterns – NREN case study DoS Attack – case study Statistics with no netflow capable device – case study Other use cases
3 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy More at www.icmynet.com
4 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
All significant exporters and their interfaces All on ingress or egress
Throughput and Volume Bit/s, packet/s, flow/s In/Out + dst/src (host, services, AS)
5 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
6 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
150+ member organisations 150 000 active users
Geographically dispersed Hierarchical network: regions, cities, institutions IP address/subnet != member
7 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
Cisco NetFlow enabled on 2 central routers ICmyNet.Flow installed on 1 server
Members = subnets and Subnet Sets Specific traffic isolated with Traffic Patterns
8 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
9 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
10 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
11 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
12 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
Statistic independent to network topology Bandwidth utilization understanding
13 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
14 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
15 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
16 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
17 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
Bits and packets traffic looks normal Flows traffic shows an anomaly Anomaly related to UDP protocol and DNS service Host identified (top talker for DNS flows)
Filtered by host, protocol and service port Grouped by destination IP addresses
18 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
Attacker discovered Type of attack determined Victims identified
19 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
One main clinic with local clinic network Centralized Healthcare software system Access through server in main clinic
No NetFlow enabled devices No device access
20 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
NetFlow probe - SoftFlowd
installed on two server interfaces: to clinics and to database Netflow data exported to ICmyNet Server Privacy - NetFlow only monitors statistic, not traffic content
Local clinics identified by IP addresses
Subnets for each clinic and their department
Service/Application monitor
Traffic Pattern for each service/application of interest
21 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
NetFlow statistics without NetFlow devices
No devices purchased Statistics per clinic and department Statistics per service of interest
Better planning for future leased links and speed
Most active personnel and departments identified Periods of most activity identified L3VPN link speed optimization per clinic
Better service reliability
22 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
Alarms
Threshold based Faster reaction Reaction when needed
Conversations
Identify top End to end talkers
Bandwidth management
Monitor specific services or traffic (Viber, YouTube etc.) Implement QoS policies
23 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
Blocked traffic
Interface out is 0 (traffic pattern) Firewall check Mitigated attacks check
“Rare” protocols
Monitor protocols other than TCP and UDP (99%)
Specific ports
Most attacks utilize open ports on several applications
24 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
25 / 26 Miloš Zeković
ICmyNet Chief Customer Officer
Soneco, d.o.o. Serbia 8th September 2014
Miloš Zeković,
milos.zekovic@soneco.rs ICmyNet Chief Customer Officer Soneco d.o.o. Serbia