There's Plenty of Room at the Bottom

4,803 views

Published on

A an overview of network flow collection and an invitation to look at the fast_ip network flow platform.

Published in: Technology
0 Comments
5 Likes
Statistics
Notes
  • Be the first to comment

No Downloads
Views
Total views
4,803
On SlideShare
0
From Embeds
0
Number of Embeds
4
Actions
Shares
0
Downloads
38
Comments
0
Likes
5
Embeds 0
No embeds

No notes for slide














































  • There's Plenty of Room at the Bottom

    1. 1. There’s Plenty of Room at the Bottom: An Invitation to Explore with Network Flows Benjamin Black b@fastip.com
    2. 2. What are Flows & Why Should You Care?
    3. 3. You Should Care Because Visibility Makes Your Life Easier.
    4. 4. Network Flow Data Means Great Visibility.
    5. 5. DDoS Detection Capacity Planning Traffic Management Troubleshooting Correlation ...
    6. 6. The Nature of Flows
    7. 7. [traffic]
    8. 8. [streams]
    9. 9. [packets] Header Payload
    10. 10. [headers] Protocol Source IP Address Destination IP Address Source Port Destination Port
    11. 11. [latency]
    12. 12. [jitter]
    13. 13. [packet loss]
    14. 14. The Structure of Flows
    15. 15. [flow keys] Protocol Protocol Source IP Address Source IP Address Destination IP Address Source Port = Destination IP Address Source Port Destination Port Destination Port
    16. 16. [templates] template_id 253 protocol src IPv4 address dest IPv4 address src port dst port total octets total packets start time end time
    17. 17. [flow records] template_id 253 TCP 172.16.101.3 192.169.7.200 9801 80 27342 octets 24 packets start 28349829023 end 28356729023
    18. 18. The Ecosystem of Flows
    19. 19. [metering process] template_id 253 template_id 253 template_id 253 template_id 253 TCP TCP TCP TCP 172.16.101.3 172.16.101.3 172.16.101.3 172.16.101.3 192.169.7.200 192.169.7.200 192.169.7.200 192.169.7.200 9801 9801 9801 9801 80 80 80 80 27342 octets 27342 octets 27342 octets 27342 octets 24 packets 24 packets 24 packets 24 packets start 28349829023 start 28349829023 start 28349829023 start 28349829023 end 28356729023 end 28356729023 end 28356729023 end 28356729023
    20. 20. [observation domain] eth0 eth1 eth2
    21. 21. [collecting process] template_id 253 template_id 253 template_id 253 template_id 253 TCP TCP TCP TCP 172.16.101.3 172.16.101.3 172.16.101.3 172.16.101.3 192.169.7.200 192.169.7.200 192.169.7.200 192.169.7.200 9801 9801 9801 9801 80 80 80 80 27342 octets 27342 octets 27342 octets 27342 octets 24 packets 24 packets 24 packets 24 packets start 28349829023 start 28349829023 start 28349829023 start 28349829023 end 28356729023 end 28356729023 end 28356729023 end 28356729023 template_id 253 template_id 253 template_id 253 template_id 253 TCP TCP TCP TCP 172.16.101.3 172.16.101.3 172.16.101.3 172.16.101.3 192.169.7.200 192.169.7.200 192.169.7.200 192.169.7.200 9801 9801 9801 9801 80 80 80 80 27342 octets 27342 octets 27342 octets 27342 octets 24 packets 24 packets 24 packets 24 packets start 28349829023 start 28349829023 start 28349829023 start 28349829023 end 28356729023 end 28356729023 end 28356729023 end 28356729023 template_id 253 template_id 253 template_id 253 template_id 253 TCP TCP TCP TCP 172.16.101.3 172.16.101.3 172.16.101.3 172.16.101.3 192.169.7.200 192.169.7.200 192.169.7.200 192.169.7.200 9801 9801 9801 9801 80 80 80 80 27342 octets 27342 octets 27342 octets 27342 octets 24 packets 24 packets 24 packets 24 packets start 28349829023 start 28349829023 start 28349829023 start 28349829023 end 28356729023 end 28356729023 end 28356729023 end 28356729023
    22. 22. Storage and Analysis are Left as an Exercise for the Reader
    23. 23. Where Do Meters Run?
    24. 24. On Network Switches/Routers [often sampled]
    25. 25. Dedicated Appliances [expensive/limited storage]
    26. 26. On Hosts [where does the data go?]
    27. 27. The Classical View
    28. 28. Where is this going?
    29. 29. Where is this going? Where is this coming from?
    30. 30. The Flow View
    31. 31. TANSTAAFL
    32. 32. Flow Data Takes Up LOTS of Space
    33. 33. [often >1% total traffic]
    34. 34. LOTS of Space Means Storage Expense or Loss of Resolution or Truncation
    35. 35. LOTS of (Multi-dimensional) Data is Hard to Analyze
    36. 36. Inflexible and Limited or Expensive and Complicated
    37. 37. [apologies]
    38. 38. [resources] IPFIX WG http://datatracker.ietf.org/wg/ipfix/charter/ nProbe http://www.ntop.org/nProbe.html Cisco NetFlow Collection Engine http://www.cisco.com/en/US/products/sw/netmgtsw/ps1964/index.html Arbor Networks http://www.arbornetworks.com/ Dartware http://www.intermapper.com/products/intermapper-flows
    39. 39. [finally...]
    40. 40. fast_ip is a platform for flow analytics
    41. 41. Sign up for our beta http://fastip.com

    ×