Best Practices In Network Behavior Analysis: Part 2 of 2

Posted in NetFlow on December 5th, 2009 by mike@plixer.com
best-practices-in-network-behavior-analysis-part-2-of-2

Here is part 1 of this blog.

Detecting DDoS Attacks
A DDos attack is a tricky monster because it can look like legitimate traffic. We have come up with an algorithm for detecting DDoS attacks that from our tests seems to be accurate.  We say this because it largely reduces the risk of false positives. It involves flow volumes, byte sizes and standard deviations. Although it is fairly complicated, it will still need modifications as DDoS behavior morphs over time.

Read more »

Michael Patterson
Scrutinizer Product Manager
Follow Me on Twitter
Tags: , , , , , , , , , ,

Three free and fabulous resources for Cisco NetFlow admins, Part 1

Posted in NetFlow, NetFlow Analyzer, Scrutinizer, Security, WebNM, sFlow on August 26th, 2009 by NewsTrax
three-free-and-fabulous-resources-for-cisco-netflow-admins-part-1

To celebrate the release of Version 7.0 of Scrutinizer NetFlow and sFlow Analyzer, which is absolutely free, I thought I’d share with you three fabulous free resources for Cisco network administrators. Read more »

Tags: , , , , , , , , , ,

Stop network worms using RST/ACK Destination algorithm with Flow Analytics, NetFlow Analyzer

Posted in General on April 10th, 2009 by miltong
stop-network-worms-using-rstack-destination-algorithm-with-flow-analytics-netflow-analyzer

A couple of weeks ago I wrote a blog entitled Downadup/Conficker Worm caught by using Flow Analytics, NetFlow Analyzer which used the SYN Violation algorithm to detect its presence. Another algorithm that will help prevent worms on your network is the RST/ACK Destination algorithm.

RST/ACK Destination algorithm looks for excessive connection denials that come back from the destination host. This is very handy in detecting such small things as network misconfigurations, and big things such as worms or port scans across the network.

Since worm attacks are designed to spread throughout networks and copy themselves to other nodes it’s important to monitor the connection requests within your network. Some worms, such as the ExploreZip Worm, are designed to alter system config files. Others exploit vulnerabilities in an effort to establish backdoors to your network. With the network now compromised, these infected machines known as zombies join other networks that have also been infected. These botnets function as a channel to inject Trojans and other viruses into yours and other networks.

Detection is made easier when using RST/ACK Destination algorithm. With the help of Flow Analytics and gadgets like this, you have the visibility you need to detect malicious behavior before it causes damage.

Milton

Tags: , , , , ,