Documente Academic
Documente Profesional
Documente Cultură
1
2006 Lancope, Inc. Company Confidential All Rights Reserved
3
2006 Lancope, Inc. Company Confidential All Rights Reserved
Remote
Sites
Remote
Users
Extranet
Qu ickTime and a
TIFF (LZW) d ecompressor
are needed to see th is picture.
Flow Collector
Marketing
Sales
Servers
WHAT IS NETFLOW?
Cisco Router
5
2006 Lancope, Inc. Company Confidential All Rights Reserved
WHAT IS SFLOW?
6
2006 Lancope, Inc. Company Confidential All Rights Reserved
7
2006 Lancope, Inc. Company Confidential All Rights Reserved
Check on
current router
CPU utilization*
9
2006 Lancope, Inc. Company Confidential All Rights Reserved
Worm Infected
Host
Target Hosts
Target Port
(0x87=135)
10
src
interface
src
IP
src
port
dst
interface
dst
IP
proto
dst
port
pkts
bytes
TCP
flags
(2=SYN)
11
3. StealthWatch associates the two NetFlow records, building one stateful entry
Start Time
3/26/05 9:04
Client Host
209.182.184.2
Server Host
66.35.250.151
Server Port
80
12
2006 Lancope, Inc. Company Confidential All Rights Reserved
13
2006 Lancope, Inc. Company Confidential All Rights Reserved
Apply
Algorithms to
Flow data
Generate
Alarms, Alerts,
and Reports
Generate
Profile-Enhanced
Alarms, Alerts,
and Reports
Send SYSLOG,
SNMP, and
Emails
Perform
Mitigation Action
Display in UI
Collect,
Deduplicate, and
Process Flow
Statistics
Flow Enabled
Routers
2006 Lancope, Inc. Company Confidential All Rights Reserved
14
16
2006 Lancope, Inc. Company Confidential All Rights Reserved
17
2006 Lancope, Inc. Company Confidential All Rights Reserved
12
IDS/IPS
2 IDP/IPS
Sensors
Sensors
Required
Required
18
2006 Lancope, Inc. Company Confidential All Rights Reserved
1 NetFlow
Collector
Required
2 IDP/IPS
Sensors
Required
19
2006 Lancope, Inc. Company Confidential All Rights Reserved
Flow Duration
Client Host IP
Server Host IP
Start Time
Last Time
Status
Protocol
Server Port
Client Port
Server Packets
TCP Flags
Client Packets
Client payload
Server Payload
Source AS
Destination AS
ToS
Source Interface
Destination Interface
Kbps Rate
Server Header Bytes
Client Header Bytes
Server Payload Bytes
Client Payload Bytes
Fragmentation
Nexthop Router
Source Netmask
Target Netmask
Source IP
Target IP
Protocol
Port
Length
IP Precedence
Status
Interface
20
disable
port
Extranet
!
Marketing
Sales
StealthWatch
Servers
Qu ickTime and a
TIFF (LZW) d ecompressor
are needed to see th is picture.
21
Flow Records
Traffic Analysis
Visualization
22
2006 Lancope, Inc. Company Confidential All Rights Reserved
SUMMARY
23
2006 Lancope, Inc. Company Confidential All Rights Reserved
Thank you
Presenter:
24
2006 Lancope, Inc. Company Confidential All Rights Reserved