NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and...

26
NetFlow use cases ICmyNet / NetVizura Miloš Zeković, [email protected] ICmyNet Chief Customer Officer Soneco d.o.o. Serbia

Transcript of NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and...

Page 1: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

NetFlow use casesICmyNet / NetVizura

Miloš Zeković,[email protected]

ICmyNet Chief Customer Officer

Soneco d.o.o. Serbia

Page 2: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

2 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

Agenda

ICmyNet / NetVizura overview

Use cases / case studiesStatistics per exporter/interfaces

Traffic Patterns – NREN case study

DoS Attack – case study

Statistics with no netflow capable device – case study

Other use cases

Questions

Page 3: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

3 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

ICmyNet / NetVizura

ICmyNet → NetVizura: Rebranding in progress

NetFlow Analyzer (ICmyNet.Flow)Statistics per Traffic Patterns and subnets

Statistics per exporter/interfaces (v4)

Statistics for each node, IP hierarchy

More at www.icmynet.com

Free Academic Network Program

Page 4: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

4 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

Exporter/interface statistic

NetFlow enabled:All significant exporters and their interfaces

All on ingress or egress

Top exporters and interfaces

Top talkers by interface, host, service, …Throughput and Volume

Bit/s, packet/s, flow/s

In/Out + dst/src (host, services, AS)

Page 5: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

5 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

Exporter/interface statistic (2)

Page 6: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

6 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

NREN CS - challenge

AMRES, Serbian NREN150+ member organisations

150 000 active users

Traffic Analysis per memberGeographically dispersed

Hierarchical network: regions, cities, institutions

IP address/subnet != member

Archive network logs for 1 year

Page 7: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

7 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

NREN CS - Solution

DeploymentCisco NetFlow enabled on 2 central routers

ICmyNet.Flow installed on 1 server

Configuration of ICmyNet.FlowMembers = subnets and Subnet Sets

Specific traffic isolated with Traffic Patterns

NetFlow records in Raw Data

Page 8: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

8 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

NREN CS - Solution (2)

Traffic Pattern

Specific traffic between two networks

Page 9: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

9 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

NREN CS - Solution (3)

Page 10: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

10 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

NREN CS – solution (4)

Page 11: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

11 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

NREN CS – Solution (3)

Page 12: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

12 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

NREN CS - Results

Two NetFlow devices – full network statistic

Statistic per memberStatistic independent to network topology

Bandwidth utilization understanding

Increased security awareness

Page 13: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

13 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

DoS Attack CS

Page 14: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

14 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

DoS Attack CS (2)

Page 15: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

15 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

DoS Attack CS (3)

Page 16: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

16 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

DoS Attack CS (4)

Page 17: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

17 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

DoS Attack CS (5)

Charts:Bits and packets traffic looks normal

Flows traffic shows an anomaly

Anomaly related to UDP protocol and DNS service

Host identified (top talker for DNS flows)

Raw Data:Filtered by host, protocol and service port

Grouped by destination IP addresses

Page 18: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

18 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

DoS Attack CS – results (6)

Isolated destinationswith large number of DNS conversations

In several clicks:Attacker discovered

Type of attack determined

Victims identified

Page 19: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

19 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

No NetFlow devices CS - challenge

DZ Palilula, primary healthcare center, SerbiaOne main clinic with local clinic network

Centralized Healthcare software system

Access through server in main clinic

Leased network devices (L3VPN)No NetFlow enabled devices

No device access

Privacy issues - patient medical data

Page 20: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

20 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

No NetFlow devices CS - solution

NetFlow probe - SoftFlowdinstalled on two server interfaces: to clinics and to database

Netflow data exported to ICmyNet ServerPrivacy - NetFlow only monitors statistic, not traffic content

Local clinics identified by IP addressesSubnets for each clinic and their department

Service/Application monitorTraffic Pattern for each service/application of interest

Page 21: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

21 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

No NetFlow devices CS - Results

NetFlow statistics without NetFlow devicesNo devices purchased

Statistics per clinic and department

Statistics per service of interest

Better planning for future leased links and speedMost active personnel and departments identified

Periods of most activity identified

L3VPN link speed optimization per clinic

Better service reliability

Page 22: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

22 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

Other use cases

AlarmsThreshold basedFaster reaction

Reaction when needed

ConversationsIdentify top End to end talkers

Bandwidth managementMonitor specific services or traffic (Viber, YouTube etc.)

Implement QoS policies

Page 23: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

23 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

Other use cases (2)

Blocked trafficInterface out is 0 (traffic pattern)

Firewall check

Mitigated attacks check

“Rare” protocolsMonitor protocols other than TCP and UDP (99%)

Specific portsMost attacks utilize open ports on several applications

Page 24: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

24 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

Question time

Questions?

Page 25: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

25 / 26Miloš ZekovićICmyNet Chief Customer OfficerSoneco, d.o.o. Serbia

8th September 2014

Thank you

Page 26: NetFlow use cases - TERENA · NetFlow Analyzer (ICmyNet.Flow) Statistics per Traffic Patterns and subnets Statistics per exporter/interfaces (v4) Statistics for each node, IP hierarchy

NetFlow use casesICmyNet / NetVizura

Miloš Zeković,[email protected]

ICmyNet Chief Customer Officer

Soneco d.o.o. Serbia