SlideShare a Scribd company logo
https://FastNetMon.com
PROJECT HISTORY
• 2013 Q2 project founded
• 2013 Q3 mirror port support
• 2014 Q2 sFlow support
• 2014 Q3 Netflow 5, 9 support
• 2015 Q1 IPFIX support
• 2015 Q2 added to official FreeBSD ports
• 2016 Q3 integration with A-10 Networks TPS
• 2017 Q1 integration with Radware Defense Flow
• 2018 Q1 FastNetMon joined to WorksOnARM.com
KEY FEATURES
• Supports all types of volumetric attacks
• Does not require changes in your network
• Complete automation
• Lightning fast detection
• Software only solution
• BGP integration (BGP unicast and BGP flow spec)
• Support almost all possible traffic capture engines
KEY FEATURES FOR BUSINESS
• Reduce cost for additional capacity
• Reduce overall service downtime
• Decrease number of incoming abuses
• Additional service for customers to increase ARPU
• Reduce cost for precise DDoS filtering hardware
• Reduce cost for DDoS filtering clouds
SUPPORTED VENDORS
LIGHTNING FAST ATTACK DETECTION
• 2 seconds with mirror
• 2-3 seconds with sFlow
• 10-30 seconds with NetFlow/IPFIX
TRAFFIC CAPTURE BACKENDS
• sFlow v5 (switches)
• Netflow v5, v9 (including sampled version), v10
(IPFIX), jFlow, cFlow (routers)
• SPAN/MIRROR (1GE, 10GE, 40GE)
• Tera Flow (distributed monitoring protocol)
SUPPORTED ATTACK TYPES
• NTP, DNS, SNMP, SSDP amplification
• TCP SYN/ACK/SYN-ACK floods
• UDP floods
• Multi vector attacks
• Reflection attacks
UNLIMITED SCALABILITY
• sFlow v5 – 1.2 Tbps*
• NetFlow – 2.2 Tbps*
• Mirror/SPAN – 80 GE*
• Distributed with Tera Flow - unlimited
*all numbers for single physical server
ACTIONS TRIGGERED FOR DETECTED
ATTACK
• E-mail notification
• BGP Blackhole
• BGP flow spec, RFC 5575
• Slack notification
• API call
• Web request
• Script call
EXTREMELY FAST DELIVERY
• Works on any VM or physical server
• Less then 15 minutes to install and configure FastNetMon on new
server!
• Network Engineer friendly CLI interface
• Learn almost all configuration automatically!
DETECTION LOGIC
Two levels:
• Threshold based (based on host’s smoothed traffic)
• Hyper packet engine for deep flow / packet inspection using statistics approach
•
•
•
•
•
BETWEEN THE CLOUD AND NETWORK EQUIPMENT
• You could use FastNetMon together with precise filtering
hardware (A-10 Networks, Radware, Palo-Alto Networks)
• You could use FastNetMon with your favourite DDoS filtering
cloud
• You could use FastNetMon to isolate attacked customer in special
network using BGP or BGP or BGP Flow Spec redirect
FRIENDLY COMMAND LINE INTERFACE
ATTACK AND TRAFFIC VISUALIZATION
ATTACK NOTIFICATIONS
RICH ATTACK REPORTS
IP: 10.10.10.221Attack type: syn_flood
Initial attack power: 546475 packets per second
Peak attack power: 546475 packets per second
Attack direction: incoming
Attack protocol: tcp
Total incoming traffic: 245 mbps
Total outgoing traffic: 0 mbps
Total incoming pps: 99059 packets per second
Total outgoing pps: 0 packets per second
Total incoming flows: 98926 flows per second
Total outgoing flows: 0 flows per second
Average incoming traffic: 45 mbps
Average outgoing traffic: 0 mbps
Average incoming pps: 99059 packets per second
Average outgoing pps: 0 packets per second
Average incoming flows: 98926 flows per second
Average outgoing flows: 0 flows per second
Incoming ip fragmented traffic: 250 mbps
Outgoing ip fragmented traffic: 0 mbps
Incoming ip fragmented pps: 546475 packets per second
Outgoing ip fragmented pps: 0 packets per second
Incoming tcp traffic: 250 mbps
Outgoing tcp traffic: 0 mbps
Incoming tcp pps: 546475 packets per second
Outgoing tcp pps: 0 packets per second
Incoming syn tcp traffic: 250 mbps
Outgoing syn tcp traffic: 0 mbps
Incoming syn tcp pps: 546475 packets per second
Outgoing syn tcp pps: 0 packets per second
Incoming udp traffic: 0 mbps
Outgoing udp traffic: 0 mbps
Incoming udp pps: 0 packets per second
Outgoing udp pps: 0 packets per second
Incoming icmp traffic: 0 mbps
Outgoing icmp traffic: 0 mbps
DISTRIBUTED SETUP WITH TERA FLOW
DEVELOPER FRIENDLY
• API for FastNetMon operations (using fcli)
• MongoDB for configuration
• JSON everywhere
• API for traffic persistency
• API for metrics
TRAFFIC PERSISTENCY
ASN REPORTS
Thank you!
sales@fastnetmon.com

More Related Content

PDF
FastNetMon - ENOG9 speech about DDoS mitigation
PDF
Ripe71 FastNetMon open source DoS / DDoS mitigation
PDF
Linux Networking Explained
PDF
netfilter and iptables
PPT
PDF
Protocole OSPF
ODP
Dpdk performance
PPTX
BGP Update Source
FastNetMon - ENOG9 speech about DDoS mitigation
Ripe71 FastNetMon open source DoS / DDoS mitigation
Linux Networking Explained
netfilter and iptables
Protocole OSPF
Dpdk performance
BGP Update Source

What's hot (20)

PDF
LinuxCon 2015 Linux Kernel Networking Walkthrough
PDF
DevConf 2014 Kernel Networking Walkthrough
PPTX
FD.io VPP事始め
PPTX
Software-Defined Networking (SDN): Unleashing the Power of the Network
PDF
DoS and DDoS mitigations with eBPF, XDP and DPDK
PPTX
The TCP/IP Stack in the Linux Kernel
PDF
BPF - in-kernel virtual machine
PDF
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpec
PDF
DDoS Mitigation using BGP Flowspec
PDF
Replacing iptables with eBPF in Kubernetes with Cilium
PDF
Using GTP on Linux with libgtpnl
PPTX
The Basic Introduction of Open vSwitch
PDF
MPLS L3 VPN Deployment
PPTX
Introduction to DPDK
PDF
cours ospf
PDF
BPF: Tracing and more
PDF
Iptables presentation
PPTX
Présentation de la pile réseau sous gnu linux
PDF
Network security
PDF
EBPF and Linux Networking
LinuxCon 2015 Linux Kernel Networking Walkthrough
DevConf 2014 Kernel Networking Walkthrough
FD.io VPP事始め
Software-Defined Networking (SDN): Unleashing the Power of the Network
DoS and DDoS mitigations with eBPF, XDP and DPDK
The TCP/IP Stack in the Linux Kernel
BPF - in-kernel virtual machine
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpec
DDoS Mitigation using BGP Flowspec
Replacing iptables with eBPF in Kubernetes with Cilium
Using GTP on Linux with libgtpnl
The Basic Introduction of Open vSwitch
MPLS L3 VPN Deployment
Introduction to DPDK
cours ospf
BPF: Tracing and more
Iptables presentation
Présentation de la pile réseau sous gnu linux
Network security
EBPF and Linux Networking
Ad

Similar to FastNetMon Advanced DDoS detection tool (20)

PDF
DDOS Mitigation Experience from IP ServerOne by CL Lee
PPTX
Integrating Unified Communications and Collaboration on an Aruba Access Network
PDF
Continuum pcap-oem
PDF
Accelerated SDN in Azure
PDF
DDoS Attacks - Scenery, Evolution and Mitigation
PDF
Leveraging Network Offload to Accelerate SDN and NFV Deployments
PDF
DDoS Mitigation Tools and Techniques
PDF
Detecting Spoofing at IXPs
PDF
Detecting spoofing at IxP's
PDF
Using MikroTik routers for BGP transit and IX points
PDF
[En] IPVS for Docker Containers
PDF
IPVS for Docker Containers
PDF
DDoS Attacks in 2017: Beyond Packet Filtering
PPTX
Tale of a New Bangladeshi NIX
PDF
Exploiting First Hop Protocols to Own the Network - Paul Coggin
PPTX
BGP Flowspec (RFC5575) Case study and Discussion
PDF
FastNetMon and Metrics
PDF
DDos, Peering, Automation and more
PDF
Netflix Open Connect: Delivering Internet TV to the world
PDF
TRex Traffic Generator - Hanoch Haim
DDOS Mitigation Experience from IP ServerOne by CL Lee
Integrating Unified Communications and Collaboration on an Aruba Access Network
Continuum pcap-oem
Accelerated SDN in Azure
DDoS Attacks - Scenery, Evolution and Mitigation
Leveraging Network Offload to Accelerate SDN and NFV Deployments
DDoS Mitigation Tools and Techniques
Detecting Spoofing at IXPs
Detecting spoofing at IxP's
Using MikroTik routers for BGP transit and IX points
[En] IPVS for Docker Containers
IPVS for Docker Containers
DDoS Attacks in 2017: Beyond Packet Filtering
Tale of a New Bangladeshi NIX
Exploiting First Hop Protocols to Own the Network - Paul Coggin
BGP Flowspec (RFC5575) Case study and Discussion
FastNetMon and Metrics
DDos, Peering, Automation and more
Netflix Open Connect: Delivering Internet TV to the world
TRex Traffic Generator - Hanoch Haim
Ad

More from Pavel Odintsov (20)

PDF
BGP Flow Spec HKNOG 13
PDF
DDoS Challenges in IPv6 environment
PDF
Network telemetry for DDoS detection presentation
PPTX
BGP FlowSpec experience and future developments
PDF
VietTel AntiDDoS Volume Based
PDF
DDoS Defense Mechanisms for IXP Infrastructures
PPTX
Flowspec contre les attaques DDoS : l'expérience danoise
PDF
Detectando DDoS e intrusiones con RouterOS
PPTX
DeiC DDoS Prevention System - DDPS
PDF
Lekker weer nlnog_nlnog_ddos_fl
PDF
Lekker weer nlnog_how_to_avoid_buying_expensive_routers
PDF
Implementing BGP Flowspec at IP transit network
PDF
Janog 39: speech about FastNetMon by Yutaka Ishizaki
PDF
Protect your edge BGP security made simple
PDF
Keeping your rack cool
PDF
Jon Nield FastNetMon
PDF
Detecting and mitigating DDoS ZenDesk by Vicente De Luca
PDF
Blackholing from a_providers_perspektive_theo_voss
PDF
SIG-NOC Tools Survey
PDF
DDoS detection at small ISP by Wardner Maia
BGP Flow Spec HKNOG 13
DDoS Challenges in IPv6 environment
Network telemetry for DDoS detection presentation
BGP FlowSpec experience and future developments
VietTel AntiDDoS Volume Based
DDoS Defense Mechanisms for IXP Infrastructures
Flowspec contre les attaques DDoS : l'expérience danoise
Detectando DDoS e intrusiones con RouterOS
DeiC DDoS Prevention System - DDPS
Lekker weer nlnog_nlnog_ddos_fl
Lekker weer nlnog_how_to_avoid_buying_expensive_routers
Implementing BGP Flowspec at IP transit network
Janog 39: speech about FastNetMon by Yutaka Ishizaki
Protect your edge BGP security made simple
Keeping your rack cool
Jon Nield FastNetMon
Detecting and mitigating DDoS ZenDesk by Vicente De Luca
Blackholing from a_providers_perspektive_theo_voss
SIG-NOC Tools Survey
DDoS detection at small ISP by Wardner Maia

Recently uploaded (20)

PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
cuic standard and advanced reporting.pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
Spectral efficient network and resource selection model in 5G networks
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PPTX
Spectroscopy.pptx food analysis technology
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Cloud computing and distributed systems.
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Encapsulation_ Review paper, used for researhc scholars
Digital-Transformation-Roadmap-for-Companies.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Understanding_Digital_Forensics_Presentation.pptx
Reach Out and Touch Someone: Haptics and Empathic Computing
MIND Revenue Release Quarter 2 2025 Press Release
The Rise and Fall of 3GPP – Time for a Sabbatical?
cuic standard and advanced reporting.pdf
Empathic Computing: Creating Shared Understanding
Spectral efficient network and resource selection model in 5G networks
The AUB Centre for AI in Media Proposal.docx
Agricultural_Statistics_at_a_Glance_2022_0.pdf
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Spectroscopy.pptx food analysis technology
20250228 LYD VKU AI Blended-Learning.pptx
Cloud computing and distributed systems.
Unlocking AI with Model Context Protocol (MCP)
Dropbox Q2 2025 Financial Results & Investor Presentation
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Network Security Unit 5.pdf for BCA BBA.
Encapsulation_ Review paper, used for researhc scholars

FastNetMon Advanced DDoS detection tool

  • 2. PROJECT HISTORY • 2013 Q2 project founded • 2013 Q3 mirror port support • 2014 Q2 sFlow support • 2014 Q3 Netflow 5, 9 support • 2015 Q1 IPFIX support • 2015 Q2 added to official FreeBSD ports • 2016 Q3 integration with A-10 Networks TPS • 2017 Q1 integration with Radware Defense Flow • 2018 Q1 FastNetMon joined to WorksOnARM.com
  • 3. KEY FEATURES • Supports all types of volumetric attacks • Does not require changes in your network • Complete automation • Lightning fast detection • Software only solution • BGP integration (BGP unicast and BGP flow spec) • Support almost all possible traffic capture engines
  • 4. KEY FEATURES FOR BUSINESS • Reduce cost for additional capacity • Reduce overall service downtime • Decrease number of incoming abuses • Additional service for customers to increase ARPU • Reduce cost for precise DDoS filtering hardware • Reduce cost for DDoS filtering clouds
  • 6. LIGHTNING FAST ATTACK DETECTION • 2 seconds with mirror • 2-3 seconds with sFlow • 10-30 seconds with NetFlow/IPFIX
  • 7. TRAFFIC CAPTURE BACKENDS • sFlow v5 (switches) • Netflow v5, v9 (including sampled version), v10 (IPFIX), jFlow, cFlow (routers) • SPAN/MIRROR (1GE, 10GE, 40GE) • Tera Flow (distributed monitoring protocol)
  • 8. SUPPORTED ATTACK TYPES • NTP, DNS, SNMP, SSDP amplification • TCP SYN/ACK/SYN-ACK floods • UDP floods • Multi vector attacks • Reflection attacks
  • 9. UNLIMITED SCALABILITY • sFlow v5 – 1.2 Tbps* • NetFlow – 2.2 Tbps* • Mirror/SPAN – 80 GE* • Distributed with Tera Flow - unlimited *all numbers for single physical server
  • 10. ACTIONS TRIGGERED FOR DETECTED ATTACK • E-mail notification • BGP Blackhole • BGP flow spec, RFC 5575 • Slack notification • API call • Web request • Script call
  • 11. EXTREMELY FAST DELIVERY • Works on any VM or physical server • Less then 15 minutes to install and configure FastNetMon on new server! • Network Engineer friendly CLI interface • Learn almost all configuration automatically!
  • 12. DETECTION LOGIC Two levels: • Threshold based (based on host’s smoothed traffic) • Hyper packet engine for deep flow / packet inspection using statistics approach • • • • •
  • 13. BETWEEN THE CLOUD AND NETWORK EQUIPMENT • You could use FastNetMon together with precise filtering hardware (A-10 Networks, Radware, Palo-Alto Networks) • You could use FastNetMon with your favourite DDoS filtering cloud • You could use FastNetMon to isolate attacked customer in special network using BGP or BGP or BGP Flow Spec redirect
  • 15. ATTACK AND TRAFFIC VISUALIZATION
  • 17. RICH ATTACK REPORTS IP: 10.10.10.221Attack type: syn_flood Initial attack power: 546475 packets per second Peak attack power: 546475 packets per second Attack direction: incoming Attack protocol: tcp Total incoming traffic: 245 mbps Total outgoing traffic: 0 mbps Total incoming pps: 99059 packets per second Total outgoing pps: 0 packets per second Total incoming flows: 98926 flows per second Total outgoing flows: 0 flows per second Average incoming traffic: 45 mbps Average outgoing traffic: 0 mbps Average incoming pps: 99059 packets per second Average outgoing pps: 0 packets per second Average incoming flows: 98926 flows per second Average outgoing flows: 0 flows per second Incoming ip fragmented traffic: 250 mbps Outgoing ip fragmented traffic: 0 mbps Incoming ip fragmented pps: 546475 packets per second Outgoing ip fragmented pps: 0 packets per second Incoming tcp traffic: 250 mbps Outgoing tcp traffic: 0 mbps Incoming tcp pps: 546475 packets per second Outgoing tcp pps: 0 packets per second Incoming syn tcp traffic: 250 mbps Outgoing syn tcp traffic: 0 mbps Incoming syn tcp pps: 546475 packets per second Outgoing syn tcp pps: 0 packets per second Incoming udp traffic: 0 mbps Outgoing udp traffic: 0 mbps Incoming udp pps: 0 packets per second Outgoing udp pps: 0 packets per second Incoming icmp traffic: 0 mbps Outgoing icmp traffic: 0 mbps
  • 19. DEVELOPER FRIENDLY • API for FastNetMon operations (using fcli) • MongoDB for configuration • JSON everywhere • API for traffic persistency • API for metrics