NetFlow Analyzer for the iPhone

Posted in network security, network threat detection, Network traffic monitoring on May 8th, 2013 by Danny
NetFlow Analyzer for the iPhone

Our NetFlow Analyzer for the iPhone takes Network traffic monitoring to a whole new dimension. Aside from receiving  email alerts on network threats, you now have the ability to dive into NetFlow Analysis right on your iPhone. From anywhere, get detailed information on your network traffic, and quickly initiate an informed response to network threats.

Cybert threat detection Read more »

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , , , ,

Cisco ASA Cyber Threat Defense: Part 1

Posted in ASA, Cisco NetFlow, cyber crime, detect network threats, detecting malware, internet security, internet threat, ip host reputation, netflow and ipfix, NetFlow Security, network security, network threat detection, NSEL, threat detection on March 6th, 2013 by Jimmy W
Cisco ASA Cyber Threat Defense: Part 1

The Cisco ASA Cyber Threat Defense solution is made up of 3 components.  The first is a basic network threat detection tool and is enabled by default on all ASA’s with 8.0(2) or later firmware. Basic threat detection monitors the rate at which packets are dropped by the ASA device. Because it is just monitoring for dropped packets across the whole appliance, the information is typically not enough to provide information about the source or nature of a malicious threat but could be a sign that some sort of nefarious activity is occurring and can be very useful for internet threat defense when exported to a logging tool using NSEL or syslogs. Read more »

Jimmy Wendler

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , , , , , ,

Solera IPFIX Support: Network Security Appliance Exports Flows

Posted in IPFIX, network security, syslog ot IPFIX on January 6th, 2013 by tomp@plixer.com
Solera IPFIX Support: Network Security Appliance Exports Flows

Good news: Solera IPFIX support is available in our IPFIX reporting solution.  This is no surprise as Flow Analysis (NetFlow and IPFIX) continue to gain popularity in several key areas of many IT security programs:

  • Data reconnaissance on the source or perpetrator of the threat (i.e. who did what to whom, when and where)
  • Merge with other data sources to gain greater contextual information surrounding the details of the malware
  • Host Reputation look ups

For those of you who need to get this setup fast, here are the instructions that we got from the documentation.
Read more »

- Thomas Pore

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , ,

NetFlow Generators: Enabling NetFlow Without NetFlow Support (Part #1)

Posted in application aware netflow, Cisco NetFlow, IPFIX, netflow probe, network security, network threat detection on November 27th, 2012 by Adam Powers
NetFlow Generators: Enabling NetFlow Without NetFlow Support (Part #1)

Introducing NetFlow and IPFIX

This article covers the benefits and capabilities provided by a new class of network monitoring technology called a NetFlow generator. But before we get too far into NetFlow generation details, let’s do a quick review of NetFlow itself for those that are new to the topic.

NetFlow and IPFIX are network monitoring technologies providing deep visibility into network traffic. NetFlow was originally developed by Cisco and later standardized into IPFIX by RFC 5101. Traditionally, NetFlow was included as a feature of routers, switches, firewalls, and other network devices. It’s even found in virtualization platforms such as VMWare’s vSphere 5.0 and above. Any device that can generate NetFlow packets is called an exporter. As packets travel through the exporter the device records information about the flow of traffic. Data elements such as packet count, source and destination IP, MAC address, and much more are stored in a memory resident data structure within the exporter called a cache. As the flows time out they are placed into a UDP datagram and sent across the network to a NetFlow Collector. The diagram below illustrates the process.

How NetFlow works

Once enabled NetFlow is used for a variety of network operations and security tasks including:

Read more »

Adam Powers
@adampowers22

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Network Forensics and Incident Response Using NetFlow and IPFIX

Posted in advanced persistent threats, Cisco NetFlow, network security, Security on November 10th, 2012 by Adam Powers
Network Forensics and Incident Response Using NetFlow and IPFIX

netflow for network forensicsNetwork forensics can be an intimidating subject. When IT personnel hear the word “forensics” they often recoil with visions of complicated software such as EnCase. Or they may think about expensive packet capture solutions such as Niksun’s NetDetector product line. While these tools can serve a specific purpose, your first line of network forensics defense should always be found in NetFlow and IPFIX…

Read more »

Adam Powers
@adampowers22

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , ,

Identity-Aware NetFlow: PCI Compliance and Beyond

Posted in Compliance, IPFIX, network security, Network traffic monitoring, Security on September 18th, 2012 by Jimmyd
Identity-Aware NetFlow:  PCI Compliance and Beyond

A twitter feed debating Australia’s  purposed government plans to log internet traffic caught my attention this morning and got me thinking about Identity Aware NetFlow.  Although storing user information is a hot topic for many countries around the world, the fact is that there are quite a few data retention laws that already exist .  Many companies are required to adhere to compliance laws and are scrambling to meet these requirements. This is why Identity Aware NetFlow has become such a valuable asset; it helps these companies meet their requirements with minimal overhead. It does this by using NetFlow/IPFIX technology which is already a part of their router or switches OS. Read more »


Jimmy D the Netflow Detective

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Join the NetFlow Developments group on LinkedIn.

Tags: , , , , ,

Barracuda IPFIX Support: Network Threat Detection

Posted in advanced persistent threats, detect network threats, NetFlow Security, Netflow Traffic Analysis, network security on August 22nd, 2012 by Scottr
Barracuda IPFIX Support: Network Threat Detection

Earlier this year Barracuda Networks enabled IPFIX support on their NG Series firewalls. This export provides great visibility into your network traffic as well as network Threat Detection.

Let’s take a moment to go over the configuration to get these exports going:

Read more »

Scott Robertson
Sr. Solutions Engineer

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!



Tags: , , , ,

Identity-Aware NetFlow: Cisco ASA NSEL

Posted in ASA, network security on July 17th, 2012 by mike@plixer.com
Identity-Aware NetFlow: Cisco ASA NSEL

Businesses with IT Teams managing tens of thousands of IP addresses often find it more difficult to track down IP addresses and for this reason, they would rather work with a username. Identity Aware NetFlow ties the two together. In this post, lets take an example of tracking down the root cause of a network security issue or detected threat.
Read more »

Michael Patterson
Founder and CEO

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , , ,