Using NetFlow to tell if your network is part of a botnet, Part 2

Posted in IT News, NetFlow, NetFlow Analyzer, Network Traffic Analysis, Network Traffic Monitor, Scrutinizer, Security on August 19th, 2009 by NewsTrax
using-netflow-to-tell-if-your-network-is-part-of-a-botnet-part-2

This is the final part in a two-part blog series on using Cisco NetFlow to identify if your network is part of a botnet. Part 1 gave a quick overview of distributed denial of service (DDoS) attacks and how they’re often caused by botnets flooding Web sites with requests, thus making the Web site inaccessible to others.

It’s not just home computers that could be part of botnets. Any work computer could be compromised if users unwittingly download malware or visit malicious Web sites, putting corporate networks at risk.  How can Cisco NetFlow be used to identify DDoS attacks?

Watch the flow behavior
Network traffic monitoring using Cisco NetFlow can help identify suspicious behavior.  Use the Scrutinizer Vitals to see if a recent spike in overall flow volume collectively from all your routers has occurred:

Network traffic flow volume
Once you identify the router kicking out massive amounts of flows, drill in to determine who is receiving the most flows:

Network traffic flow volume 2
Use flow analytics

Scanning for threats from external sources can be used to identify whether an internal computer is part of a botnet. The Flow Analytics module of Scrutinizer features an Internet Threats Monitor that monitors all connections in and out of the Internet for such behavior. Flow Analytics, when used with the RST/ACK Destination algorithm and SYN Violation algorithm can help catch network worms.

“Network Behavior Analysis with Flow Analytics is an important part of our NetFlow Analysis software,” says Michael Patterson, Scrutinizer product manager. Our solution looks for network threats across hundreds of routers and deduplicates flows to ensure an accurate Unique Index is compiled per host. DDoS attack behaviors can be identified with well engineered mathematical algorithms.”

Here are some interesting links for further reading on botnets:

How my computer became a zombie

How Can I Tell If My Computer Is Part of a Botnet?

Busting bots: Defending against botnets

Share and Enjoy:
  • Digg
  • StumbleUpon
  • Reddit
  • del.icio.us
  • Facebook
  • Yahoo! Buzz
  • Google Bookmarks
  • Technorati
  • Twitter
  • email
  • Print
Tags: , , , , , , , , , , , ,

2 Responses to “Using NetFlow to tell if your network is part of a botnet, Part 2”

  1. Using NetFlow to tell if your network is part of a botnet, Part 1 - NetFlow & sFlow Network Monitoring - Systrax Blog Says:

    [...] more in part 2 of this blog series on how to identify a DDoS attack using NetFlow. Share and [...]

  2. Three free and fabulous resources for Cisco network admins, Part 1 - NetFlow & sFlow Network Monitoring - Systrax Blog Says:

    [...] * Invisible Attackers: Stop the Bot: This episode discusses tools and techniques used by hackers to infiltrate networks. (Also, read our two-part blog series on using NetFlow to tell if your network is part of a botnet.) [...]

Leave a Reply