SlideShare a Scribd company logo
@Rathaur_Kamal
 Infosec Enthusiast
 Incident Response/Digital Forensics Analyst
 Speaker/Volunteer at Null and OWASP
chapters
 AM – IT Security (Just a position, for the
records) 
 Travelling, Trekking, Infosec brainstorming
 GCFA Certified, SANS Lethal Forensicator
Award
 A series of packets on a network that have common attributes
 Just metadata – No contents
 Much like a phone bill – You know, who called who but not
what was said
 Is not a replacement for full packet capture
Go with the flow
Go with the flow
 Exporter – Uses UDP (Standard port 2055) for sending
packets to Collectors
 Collectors – Positioning is the key
 Storage – Understand the requirements and the size of
storage based on the need
 Analysis Console – usually a thin client – browser
based. Performance hungry
 Identify the critical data
 Understand the network diagram
 Identify choke and critical nodes
 Identify critical datacenters
 Plan Netflow exporters and packet capture
points
 Confirm legal and regulatory compliance
 Security teams may prefer to use their own
Netflow server and storage solution
nfcapd - netflow capture daemon
nfdump - netflow dump
nfprofile - netflow profiler
nfreplay - netflow replay
nfclean.pl - cleanup old data
ft2nfdump - optional binary
 A set of tools to collect and process netflow data
 Supports netflow versions v1, v5, v7, v9 and IPFIX
 Fully IPv6 compatible
 Stores netflow data in time sliced files – rotates typically every
5 minutes i.e. 288 files per day in nfcapd.YYYYMmddhhmm
format
 Command line based tool compatible to tcpdump
 Top N statistics for packets, bytes, IP addresses, ports…
Date flow start Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows
2005-08-30 06:59:52.338 0.001 UDP 36.249.80.226:3040 -> 92.98.219.116:1434 1 404 1
Go with the flow
 NfSen is a graphical web based front end for the Nfdump
netflow tools
 Graph specific profiles
• Track hosts, ports etc. from live data
• Profile hosts involved in incidents from history data
 Analyze a specific time window
 Web based
 Automatic alerting
 Flexible extensions using plugins
Go with the flow
Demo Time
 Understand the netflow basics
 Netflow Analysis with open source tools
 Ideas for setting up test lab
 Testing and Deployment in VM
 Replicate to Production environment
Go with the flow
Thank You!

More Related Content

PDF
Delegation-based Authentication and Authorization for the IP-based IoT
DOCX
Poll mode driver integration into dpdk
PDF
Lithe: Lightweight Secure CoAP for the Internet of Things
PDF
Linux Kernel Cryptographic API and Use Cases
PPTX
Mmap failure analysis
PDF
nextcomputing-packet-continuum
PDF
Accelerating Networked Applications with Flexible Packet Processing
PDF
Measuring a 25 and 40Gb/s Data Plane
Delegation-based Authentication and Authorization for the IP-based IoT
Poll mode driver integration into dpdk
Lithe: Lightweight Secure CoAP for the Internet of Things
Linux Kernel Cryptographic API and Use Cases
Mmap failure analysis
nextcomputing-packet-continuum
Accelerating Networked Applications with Flexible Packet Processing
Measuring a 25 and 40Gb/s Data Plane

What's hot (20)

PDF
Kernel Recipes 2017 - EBPF and XDP - Eric Leblond
PPTX
Network based file carving
PPTX
Dpdk – IoT packet analyzer
PDF
Comprehensive XDP Off‌load-handling the Edge Cases
PPTX
Forensic Analysis - Empower Tech Days 2013
PDF
LF_DPDK17_DPDK support for new hardware offloads
PPTX
Compiling P4 to XDP, IOVISOR Summit 2017
PDF
Telco junho cost-effective approach for telco network analysis in 5_g_final
PDF
Group meeting: TaintPipe - Pipelined Symbolic Taint Analysis
PDF
P4, EPBF, and Linux TC Offload
PDF
Network Measurement with P4 and C on Netronome Agilio
PDF
How Robinhood Built a Real-Time Anomaly Detection System to Monitor and Mitig...
PDF
Using IO Visor to Secure Microservices Running on CloudFoundry [OpenStack Sum...
PDF
Apache Solr as a compressed, scalable, and high performance time series database
PDF
Kernel Recipes 2013 - Nftables, what motivations and what solutions
PDF
OXiGen: Automated FPGA design flow from C applications to dataflow kernels - ...
PPTX
Debug generic process
PDF
BPF & Cilium - Turning Linux into a Microservices-aware Operating System
PPTX
Monitoring and Alerting with InfluxDB 2.0 | Deniz Kusefoglu & Nate Isley | In...
PDF
Ceph Day Shanghai - On the Productization Practice of Ceph
Kernel Recipes 2017 - EBPF and XDP - Eric Leblond
Network based file carving
Dpdk – IoT packet analyzer
Comprehensive XDP Off‌load-handling the Edge Cases
Forensic Analysis - Empower Tech Days 2013
LF_DPDK17_DPDK support for new hardware offloads
Compiling P4 to XDP, IOVISOR Summit 2017
Telco junho cost-effective approach for telco network analysis in 5_g_final
Group meeting: TaintPipe - Pipelined Symbolic Taint Analysis
P4, EPBF, and Linux TC Offload
Network Measurement with P4 and C on Netronome Agilio
How Robinhood Built a Real-Time Anomaly Detection System to Monitor and Mitig...
Using IO Visor to Secure Microservices Running on CloudFoundry [OpenStack Sum...
Apache Solr as a compressed, scalable, and high performance time series database
Kernel Recipes 2013 - Nftables, what motivations and what solutions
OXiGen: Automated FPGA design flow from C applications to dataflow kernels - ...
Debug generic process
BPF & Cilium - Turning Linux into a Microservices-aware Operating System
Monitoring and Alerting with InfluxDB 2.0 | Deniz Kusefoglu & Nate Isley | In...
Ceph Day Shanghai - On the Productization Practice of Ceph
Ad

Viewers also liked (7)

PDF
Scalable Monitoring & Alerting
PDF
Managing Tech Teams (Dev StackUp)
PDF
An Introduction to Rearview - Time Series Based Monitoring
PDF
Graphite
PDF
Stop pulling the plug
PDF
PDF
Collecting metrics with Graphite and StatsD
Scalable Monitoring & Alerting
Managing Tech Teams (Dev StackUp)
An Introduction to Rearview - Time Series Based Monitoring
Graphite
Stop pulling the plug
Collecting metrics with Graphite and StatsD
Ad

Similar to Go with the flow (20)

PPTX
Open source network forensics and advanced pcap analysis
PDF
Go with the Flow-v2
PDF
Network Security and Visibility through NetFlow
PDF
Network Security: Experiment of Network Health Analysis At An ISP
PDF
Flow Monitoring Tools, What do we have, What do we need?
PDF
MMIX Peering Forum and MMNOG 2020: Packet Analysis for Network Security
PPTX
NFA - Middle East Workshop
DOCX
Task 803   - 1 page Instructions Distinguish between full con.docx
DOCX
Chapter 3. sensors in the network domain
PPTX
Leverage the Network to Detect and Manage Threats
PDF
CNIT 40: 4: Monitoring and detecting security breaches
PPT
Network Security Data Visualization
PDF
Flow questions and answers
PDF
Analytics and Visualization in your Secured Infrastructure Network.
PDF
IT Monitoring in the Era of Containers | Luca Deri Founder & Project Lead | ntop
PDF
Network traffic analysis course
PDF
25.3.10 packet tracer explore a net flow implementation
PDF
May The Data Stay with U! Network Data Exfiltration Techniques - Brucon 2017.
PDF
Just two clicks away - from monitoring and reporting to root-cause analysis
Open source network forensics and advanced pcap analysis
Go with the Flow-v2
Network Security and Visibility through NetFlow
Network Security: Experiment of Network Health Analysis At An ISP
Flow Monitoring Tools, What do we have, What do we need?
MMIX Peering Forum and MMNOG 2020: Packet Analysis for Network Security
NFA - Middle East Workshop
Task 803   - 1 page Instructions Distinguish between full con.docx
Chapter 3. sensors in the network domain
Leverage the Network to Detect and Manage Threats
CNIT 40: 4: Monitoring and detecting security breaches
Network Security Data Visualization
Flow questions and answers
Analytics and Visualization in your Secured Infrastructure Network.
IT Monitoring in the Era of Containers | Luca Deri Founder & Project Lead | ntop
Network traffic analysis course
25.3.10 packet tracer explore a net flow implementation
May The Data Stay with U! Network Data Exfiltration Techniques - Brucon 2017.
Just two clicks away - from monitoring and reporting to root-cause analysis

Recently uploaded (20)

PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PPTX
Tartificialntelligence_presentation.pptx
PPTX
Chapter 5: Probability Theory and Statistics
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
DP Operators-handbook-extract for the Mautical Institute
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Mushroom cultivation and it's methods.pdf
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
A Presentation on Touch Screen Technology
PDF
project resource management chapter-09.pdf
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
Enhancing emotion recognition model for a student engagement use case through...
Assigned Numbers - 2025 - Bluetooth® Document
Tartificialntelligence_presentation.pptx
Chapter 5: Probability Theory and Statistics
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
A comparative study of natural language inference in Swahili using monolingua...
DP Operators-handbook-extract for the Mautical Institute
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Encapsulation_ Review paper, used for researhc scholars
Building Integrated photovoltaic BIPV_UPV.pdf
Mushroom cultivation and it's methods.pdf
1 - Historical Antecedents, Social Consideration.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
A Presentation on Touch Screen Technology
project resource management chapter-09.pdf
SOPHOS-XG Firewall Administrator PPT.pptx
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
Programs and apps: productivity, graphics, security and other tools
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf

Go with the flow

  • 2.  Infosec Enthusiast  Incident Response/Digital Forensics Analyst  Speaker/Volunteer at Null and OWASP chapters  AM – IT Security (Just a position, for the records)   Travelling, Trekking, Infosec brainstorming  GCFA Certified, SANS Lethal Forensicator Award
  • 3.  A series of packets on a network that have common attributes  Just metadata – No contents  Much like a phone bill – You know, who called who but not what was said  Is not a replacement for full packet capture
  • 6.  Exporter – Uses UDP (Standard port 2055) for sending packets to Collectors  Collectors – Positioning is the key  Storage – Understand the requirements and the size of storage based on the need  Analysis Console – usually a thin client – browser based. Performance hungry
  • 7.  Identify the critical data  Understand the network diagram  Identify choke and critical nodes  Identify critical datacenters  Plan Netflow exporters and packet capture points  Confirm legal and regulatory compliance  Security teams may prefer to use their own Netflow server and storage solution
  • 8. nfcapd - netflow capture daemon nfdump - netflow dump nfprofile - netflow profiler nfreplay - netflow replay nfclean.pl - cleanup old data ft2nfdump - optional binary
  • 9.  A set of tools to collect and process netflow data  Supports netflow versions v1, v5, v7, v9 and IPFIX  Fully IPv6 compatible  Stores netflow data in time sliced files – rotates typically every 5 minutes i.e. 288 files per day in nfcapd.YYYYMmddhhmm format  Command line based tool compatible to tcpdump  Top N statistics for packets, bytes, IP addresses, ports… Date flow start Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2005-08-30 06:59:52.338 0.001 UDP 36.249.80.226:3040 -> 92.98.219.116:1434 1 404 1
  • 11.  NfSen is a graphical web based front end for the Nfdump netflow tools  Graph specific profiles • Track hosts, ports etc. from live data • Profile hosts involved in incidents from history data  Analyze a specific time window  Web based  Automatic alerting  Flexible extensions using plugins
  • 14.  Understand the netflow basics  Netflow Analysis with open source tools  Ideas for setting up test lab  Testing and Deployment in VM  Replicate to Production environment