Pro+ Content/Information Security magazine

Thank you for joining!
Access your Pro+ Content below.
January 2006

Mining NetFlow

Your routers and switches can yield a mother lode of security information about your network--if you know where to dig.   Excavating endless logs to detect malicious network activity is a lot like mining for gold-- randomly digging holes to find a nugget or two isn't very efficient. Your search will be a lot more fruitful if you know what to look for and where to look for it. Fortunately, data generated by NetFlow, a de facto UDP-based traffic reporting protocol, yields a rich vein of specific information about data flow--source and destination IP addresses and port numbers, protocol and service types, and the router input interface. Mining NetFlow data can still be extremely difficult, but a handful of free and/or relatively inexpensive tools allow you to hit pay dirt by easily sorting, viewing and analyzing the information you want to use. The results can help you identify and shut down everything from spam to botnets. This technique is particularly valuable for ISPs, but can produce invaluable security information in any ...

Access this Pro+ Content for Free!

By submitting you agree to recieve email from TechTarget and its partners. If you reside outside of the United States you consent to having your personal data transferred and processed in the United States. Privacy Policy

Features in this issue

  • Mining NetFlow

    Your routers and switches can yield a mother lode of security information about your network--if you know where to dig

  • Help From Above

    Security managers are looking to the keepers of the Internet cloud for relief.

  • Secure communications

    by  Dr. Juergen Schneider

    This tip covers ways that you can secure a network to protect data from internal as well as external attacks.

Columns in this issue

SearchCloudSecurity

SearchNetworking

SearchCIO

SearchConsumerization

SearchEnterpriseDesktop

SearchCloudComputing

ComputerWeekly

-ADS BY GOOGLE

Close