SlideShare a Scribd company logo
For DDoS Detection
Applications
Network
Telemetry
Aboutme
I’m Pavel Odintsov, the author of open source DDoS
detection tool, FastNetMon:
https://github.com/pavel-odintsov/fastnetmon
Ways to contact me:
● linkedin.com/in/podintsov
● github.com/pavel-odintsov
● twitter.com/odintsov_pavel
● IRC, FreeNode, pavel_odintsov
● pavel.odintsov@gmail.com
ONPREMISE
CLOUD
NetworkTelemetryTypes
OnPremiseTelemetry
Netflow,IPFIX
sFlow
SPAN
56%
16%
28%
ProtocolsUseForDDoSDetection
Netflow
sFlow
SPAN
IPFIX, Netflow v5, Netflow v9, Netstream, jFlow, cFlow
and many others
NetflowBasedProtocols
NetflowIssues
Significantdelay
Caused by flow
aggregation engine,
varies from 3 seconds
up to 90 seconds
Flow processing engine
on many routers has
very limited CPU power
and constrained by
flow table size
For effective DDoS
detection we need
fragmentation flags,
TTLs and even part of
payload
Netflow based
protocols use very
complex way to encode
sampling
Lackofdetails
SAMPLINGRATEREPORTING
Scalabilityissues
sFlowBenefits
Verysmall/nodelay
sFlow agents do not
implement aggregation
and they keep traffic
only for very short
period of time
sFlow does not
implement any kind of
aggregation and does
not need very
efficient memory for
flow tables
Provides such
important flags as TTL
and fragmentation
fields accompanied by
first bytes of payload
Sampling rate is
encoded directly in
each packet, packet
headers exported as-is
without encoding
Keeps60+bytesfrompacket
Simpleencodingprotocol
SmallCPUoverheader
VendorsDosFlowWrong
Only small subset of
router vendors offer
sFlow support and for
few of them it just
does not work well
LackofsFlowsupport
Many vendors limit
minimum sampling rate
by extremely harsh
values (1:16000)
which makes reliable
attack detection
impossible.
In many cases due to
slow CPU on control
plane sFlow agent
cannot export all
traffic. Many
hardware platforms
have very limited
capacity towards data
plane
Scalabilityissues
Inadequatesamplingrate
10
LinuxTrafficCapture
DPDK, Netmap,
PF_RING,
SnabbSwitch
Other
Available in all
Linux
distributions
(excluding
CentOS/RHEL 6)
Available since
Linux Kernel
4.19. Ubuntu
20.04 and later
AF_PACKET
AF_XDP
BestProtocolForDDoSdetection?
sFlow
CloudNetworkAnalytics
AmazonVPCFlowlogs
Limited by 60 second delay,
expensive and complex way to export
logs
GoogleFlowLogs
Limited by UDP and TCP traffic
only, expensive and complex way to
export logs
AzureFlowLogs
Excellent visibility with Network
Traffic Watcher instrument
Any questions?
pavel.odintsov@gmail.com
THANKS
@odintsov_pavel
linkedin.com/in/podintsov

More Related Content

PDF
FastNetMon - ENOG9 speech about DDoS mitigation
PDF
FastNetMonを試してみた
PDF
Blackholing from a_providers_perspektive_theo_voss
PPTX
FastNetMon Advanced DDoS detection tool
PPT
Using system fingerprints to track attackers
PDF
Ripe71 FastNetMon open source DoS / DDoS mitigation
PDF
Distributed Denial of Service Attack - Detection And Mitigation
FastNetMon - ENOG9 speech about DDoS mitigation
FastNetMonを試してみた
Blackholing from a_providers_perspektive_theo_voss
FastNetMon Advanced DDoS detection tool
Using system fingerprints to track attackers
Ripe71 FastNetMon open source DoS / DDoS mitigation
Distributed Denial of Service Attack - Detection And Mitigation

What's hot (20)

PDF
Nanog66 vicente de luca fast netmon
PDF
Protect your edge BGP security made simple
PDF
Jon Nield FastNetMon
PDF
Keeping your rack cool
PPT
PDF
3 scanning-ger paoctes-pub
PDF
Hardening Three - IDS/IPS Technologies
PDF
DDoS Mitigation Tools and Techniques
PPTX
PDF
PPTX
DeiC DDoS Prevention System - DDPS
PDF
Detecting and mitigating DDoS ZenDesk by Vicente De Luca
PPTX
All About Snort
PDF
Preventing Traffic with Spoofed Source IP address
PDF
Cyber-security
PPTX
BGP FlowSpec experience and future developments
PPTX
G3t R00t at IUT
PDF
IDS & Passive Network Defense
PPTX
Snort
PDF
CCNA 1 Chapter 11 v5.0 2014
Nanog66 vicente de luca fast netmon
Protect your edge BGP security made simple
Jon Nield FastNetMon
Keeping your rack cool
3 scanning-ger paoctes-pub
Hardening Three - IDS/IPS Technologies
DDoS Mitigation Tools and Techniques
DeiC DDoS Prevention System - DDPS
Detecting and mitigating DDoS ZenDesk by Vicente De Luca
All About Snort
Preventing Traffic with Spoofed Source IP address
Cyber-security
BGP FlowSpec experience and future developments
G3t R00t at IUT
IDS & Passive Network Defense
Snort
CCNA 1 Chapter 11 v5.0 2014
Ad

Similar to Network telemetry for DDoS detection presentation (20)

PDF
Fortinet_FortiDDoS_Introduction
PDF
about botnets
PDF
What You Should Know Before The Next DDoS Attack
PDF
EuroBSDCon 2013 - Mitigating DDoS Attacks at Layer 7
PDF
DDoS Challenges in IPv6 environment
PDF
PLNOG14: Czy można żyć bez systemu ochrony przed atakami DDoS - Marek Janik
PDF
How OpenShift SDN helps to automate
PDF
How Printers Get Hacked ?
PDF
MUD Workshop 2025 - The rise of the machines.pdf
ODP
Zero Downtime JEE Architectures
PPTX
Cyber security2012 hybrid-hardware-software
PPS
Hacking Client Side Insecurities
PPTX
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
PPTX
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
PDF
From nothing to Prometheus : one year after
PDF
HKNOG 1.0 - DDoS attacks in an IPv6 World
PPT
DDoS Attacks and Countermeasures
ODP
DDoS - unstoppable menace
ODP
DDoS - unstoppable menace
PPT
DDOS (1).ppt
Fortinet_FortiDDoS_Introduction
about botnets
What You Should Know Before The Next DDoS Attack
EuroBSDCon 2013 - Mitigating DDoS Attacks at Layer 7
DDoS Challenges in IPv6 environment
PLNOG14: Czy można żyć bez systemu ochrony przed atakami DDoS - Marek Janik
How OpenShift SDN helps to automate
How Printers Get Hacked ?
MUD Workshop 2025 - The rise of the machines.pdf
Zero Downtime JEE Architectures
Cyber security2012 hybrid-hardware-software
Hacking Client Side Insecurities
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
NetFlow Best Practices - Tips and Tricks to Get the Most Out of Your Network ...
From nothing to Prometheus : one year after
HKNOG 1.0 - DDoS attacks in an IPv6 World
DDoS Attacks and Countermeasures
DDoS - unstoppable menace
DDoS - unstoppable menace
DDOS (1).ppt
Ad

More from Pavel Odintsov (16)

PDF
BGP Flow Spec HKNOG 13
PDF
Using MikroTik routers for BGP transit and IX points
PDF
VietTel AntiDDoS Volume Based
PDF
DDoS Defense Mechanisms for IXP Infrastructures
PPTX
Flowspec contre les attaques DDoS : l'expérience danoise
PDF
Detectando DDoS e intrusiones con RouterOS
PDF
Lekker weer nlnog_nlnog_ddos_fl
PDF
Lekker weer nlnog_how_to_avoid_buying_expensive_routers
PDF
Implementing BGP Flowspec at IP transit network
PDF
Janog 39: speech about FastNetMon by Yutaka Ishizaki
PDF
SIG-NOC Tools Survey
PDF
DDoS detection at small ISP by Wardner Maia
PDF
03 estrategia-ddos
PDF
Ultra fast DDoS Detection with FastNetMon at Coloclue (AS 8283)
PDF
GoBGP : yet another OSS BGPd
PDF
Containers in real world презентация
BGP Flow Spec HKNOG 13
Using MikroTik routers for BGP transit and IX points
VietTel AntiDDoS Volume Based
DDoS Defense Mechanisms for IXP Infrastructures
Flowspec contre les attaques DDoS : l'expérience danoise
Detectando DDoS e intrusiones con RouterOS
Lekker weer nlnog_nlnog_ddos_fl
Lekker weer nlnog_how_to_avoid_buying_expensive_routers
Implementing BGP Flowspec at IP transit network
Janog 39: speech about FastNetMon by Yutaka Ishizaki
SIG-NOC Tools Survey
DDoS detection at small ISP by Wardner Maia
03 estrategia-ddos
Ultra fast DDoS Detection with FastNetMon at Coloclue (AS 8283)
GoBGP : yet another OSS BGPd
Containers in real world презентация

Recently uploaded (20)

PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
Spectroscopy.pptx food analysis technology
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Machine learning based COVID-19 study performance prediction
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
KodekX | Application Modernization Development
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Approach and Philosophy of On baking technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
Understanding_Digital_Forensics_Presentation.pptx
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Review of recent advances in non-invasive hemoglobin estimation
Spectroscopy.pptx food analysis technology
MYSQL Presentation for SQL database connectivity
Spectral efficient network and resource selection model in 5G networks
Machine learning based COVID-19 study performance prediction
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Per capita expenditure prediction using model stacking based on satellite ima...
KodekX | Application Modernization Development
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Unlocking AI with Model Context Protocol (MCP)
NewMind AI Weekly Chronicles - August'25 Week I
Dropbox Q2 2025 Financial Results & Investor Presentation
“AI and Expert System Decision Support & Business Intelligence Systems”
Approach and Philosophy of On baking technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Understanding_Digital_Forensics_Presentation.pptx

Network telemetry for DDoS detection presentation