netvizura a network traffic analysis tool. agenda why netvizura is needed how netvizura works where...

12
NetVizura A network traffic analysis tool

Upload: may-cunningham

Post on 18-Jan-2018

221 views

Category:

Documents


0 download

DESCRIPTION

3 Why Use NetVizura?

TRANSCRIPT

Page 1: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

NetVizura

A network traffic analysis tool

Page 2: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Agenda

• Why NetVizura is needed• How NetVizura works• Where NetVizura is deployed• Use cases

Page 3: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

3

Why Use NetVizura?

Page 4: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

4

1. A flow is unidirectional2. Defined by inspecting a packet’s key fields (common properties) and

identifying the values 3. If the set of key field values is unique create a flow record or cache entry

How Does NetVizura Work?Part 1: IPFIX Flow Data

Page 5: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

How Does NetVizura Work?Part 2: Define Traffic Patterns

• Traffic pattern = IP addresses that represent an internal and external network

5

Internal Network:128.117.0.0/16

External Network:Internet

Page 6: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

NetVizura Deployment

6

Page 7: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 1: NCAR’s Top Hosts

7

Page 8: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 2: GladeWho does Glade exchange traffic with?

8

Page 9: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 3: MSUD Traffic SpikePort Utilization

9

Page 10: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 3: MSUD DOS AttackTop Hosts

10

Page 11: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 3: MSUD DOS AttackTop ASs

11

Page 12: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Questions?

12