Introducing Plixer’s Internet Threat Center (ITC)

Posted in General, internet threat center, ip host reputation, NetFlow Security, Security on December 2nd, 2012 by Adam Powers
Introducing Plixer's Internet Threat Center (ITC)

Detect Internet Threats: botnet, malware, and morePlixer is pleased to announce a new weapon in the war against Internet threats: the all new Internet Threat Center (ITC). Based on hundreds of observation points deployed across the Internet, the ITC provides a near-realtime view of malicious actors across the globe. Plixer customers gain access to the ITC via regular updates to Internet host reputation data downloaded from the ITC to their Scrutinizer installations. NetFlow data collected from routers and switches within their network is compared to ITC data to alert when ITC suspects are active within the customer’s network environment.

This blog provides an overview of the Internet Threat Center and a brief tour of its features…

Read more »

Adam Powers
@adampowers22

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , ,

Network Segmentation, Segregation, and Zero-Trust Design

Posted in NetFlow, NetFlow Analysis, NetFlow Security, Security on November 19th, 2012 by Adam Powers
Network Segmentation, Segregation, and Zero-Trust Design

segment internal network hosts from critical assetsThe Zero Trust model is a relatively new network security design model that requires network segmentation and segregation of employees from critical internal resources. The basic idea is that the internal network is no longer explicitly ”trusted.” BYOD policies and the mobile workforce have brought new threats to the internal network that just weren’t there five years ago. It’s no longer practical to assume “bad guys outside, good guys inside.” Let’s take a look at exactly what this means…

Read more »

Adam Powers
@adampowers22

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , ,

Network Forensics and Incident Response Using NetFlow and IPFIX

Posted in advanced persistent threats, Cisco NetFlow, network security, Security on November 10th, 2012 by Adam Powers
Network Forensics and Incident Response Using NetFlow and IPFIX

netflow for network forensicsNetwork forensics can be an intimidating subject. When IT personnel hear the word “forensics” they often recoil with visions of complicated software such as EnCase. Or they may think about expensive packet capture solutions such as Niksun’s NetDetector product line. While these tools can serve a specific purpose, your first line of network forensics defense should always be found in NetFlow and IPFIX…

Read more »

Adam Powers
@adampowers22

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , ,

NetFlow and IPFIX For PCI Compliance: Verify, Investigate, Impress

Posted in advanced persistent threats, Compliance, detect network threats, detecting malware, Flow Analytics, IPFIX, NetFlow, NetFlow Security on September 29th, 2012 by Adam Powers
NetFlow and IPFIX For PCI Compliance: Verify, Investigate, Impress

NetFlow and IPFIX ensure PCI compliance

At least two or three times each week we’re asked how NetFlow relates to PCI compliance. Our answer is crisp and simple. No fancy requirement references or complicated legal speak, just practical advice that’s actually useful for those concerned with the PCI audit process. There are three key areas NetFlow and IPFIX analysis can aid the enterprise as it relates to PCI:

Read more »

Tags: , , , ,

What Deep Application Awareness means to Business

Posted in application aware netflow, IPFIX on September 27th, 2012 by mike@plixer.com
What Deep Application Awareness means to Business

Deep Application Awareness is the ability to accurately identify different applications within a business.  What makes it difficult is that each application could be sharing the same ports.  A company that understands how bandwidth is being consumed, by who and how it is prioritized can optimized organizational performance.

Read more »

Michael Patterson
Founder and CEO

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , ,

Identity-Aware NetFlow: PCI Compliance and Beyond

Posted in Compliance, IPFIX, network security, Network traffic monitoring, Security on September 18th, 2012 by Jimmyd
Identity-Aware NetFlow:  PCI Compliance and Beyond

A twitter feed debating Australia’s  purposed government plans to log internet traffic caught my attention this morning and got me thinking about Identity Aware NetFlow.  Although storing user information is a hot topic for many countries around the world, the fact is that there are quite a few data retention laws that already exist .  Many companies are required to adhere to compliance laws and are scrambling to meet these requirements. This is why Identity Aware NetFlow has become such a valuable asset; it helps these companies meet their requirements with minimal overhead. It does this by using NetFlow/IPFIX technology which is already a part of their router or switches OS. Read more »


Jimmy D the Netflow Detective

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Join the NetFlow Developments group on LinkedIn.

Tags: , , , , ,

BYOD Policy Essentials: Trust But Verify

Posted in BYOD, Mobile IAM, NetFlow Security, Security on September 17th, 2012 by Adam Powers
BYOD Policy Essentials: Trust But Verify

BYOD policy assessment The IT Consumerization or “Bring Your Own Device” (BYOD) movement is already well underway and the iPhone5 launch will see even more employee sourced devices hitting the enterprise network. Even if you’re lucky enough to work for a company that provides iPhones to their employees, you probably don’t want to wait for IT to upgrade your iPhone now do you? You’ll want to BYOD.

So in support of iPhone5 users everywhere, here are three essential components of a BYOD-ready company: Policy, Education, Technology. Let’s discuss…

Read more »

Tags: , , ,

A Firewall Monitoring Tool You Didn’t Know Existed: NetFlow and IPFIX

Posted in Firewall NetFlow, Log Management, NAT Reporting, NetFlow, NetFlow NAT Reports, NetFlow Reporting, NetFlow Security, Third Party Integration on September 7th, 2012 by Adam Powers
A Firewall Monitoring Tool You Didn't Know Existed: NetFlow and IPFIX

IT professionals have been looking for better ways to monitor and store firewall logs for years. Properly handled, firewall events can give insight into APTs, DoS attacks, firewall rule planning and misconfigurations, policy violations, and much more. To date, Syslog has been the go-to mechanism for access to firewall log info. It’s universally supported by the firewall community, easy to understand, and it’s quick to implement on both the firewall as well as the syslog analyzer.

Unfortunately syslog is resource intensive on both the firewall and the log analyzer. It’s largely unstructured, requires string pattern matching, and the exact format and fields vary from one firewall to the next. How often do you turn on full “Accept” and “Deny” logging for every rule? Sure you can and yes it’s valuable but the amount of syslog created is tremendous.

Enter NetFlow and IPFIX

Read more »

Tags: , , , ,

Zenoss NetFlow Zenpack

Posted in NetFlow, Scrutinizer, Third Party Integration on September 5th, 2012 by Jimmy W
Zenoss NetFlow Zenpack

Have you been looking for a Zenpack that would allow seamless integration of Zenoss and the NetFlow tool Scrutinizer? Well you have come to the right place! Today I will be showing you how to complete the configuration of this integration. Read more »

Jimmy Wendler

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , , , , ,

NetFlow vs. sFlow for Network Monitoring and Security: The Final Say

Posted in IPFIX, NetFlow, sFlow on August 27th, 2012 by Adam Powers
NetFlow vs. sFlow for Network Monitoring and Security: The Final Say

NetFlow compared to sFlow for network monitoring

We’ve blogged about the differences between NetFlow and sFlow before but this debate continues to come up often enough and has been going on long enough that it needs to be put to rest once and for all. So let’s cut right to the chase:

Read more »

Tags: , , , ,