12
NetVizura A network traffic analysis tool

NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Embed Size (px)

DESCRIPTION

3 Why Use NetVizura?

Citation preview

Page 1: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

NetVizura

A network traffic analysis tool

Page 2: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Agenda

• Why NetVizura is needed• How NetVizura works• Where NetVizura is deployed• Use cases

Page 3: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

3

Why Use NetVizura?

Page 4: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

4

1. A flow is unidirectional2. Defined by inspecting a packet’s key fields (common properties) and

identifying the values 3. If the set of key field values is unique create a flow record or cache entry

How Does NetVizura Work?Part 1: IPFIX Flow Data

Page 5: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

How Does NetVizura Work?Part 2: Define Traffic Patterns

• Traffic pattern = IP addresses that represent an internal and external network

5

Internal Network:128.117.0.0/16

External Network:Internet

Page 6: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

NetVizura Deployment

6

Page 7: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 1: NCAR’s Top Hosts

7

Page 8: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 2: GladeWho does Glade exchange traffic with?

8

Page 9: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 3: MSUD Traffic SpikePort Utilization

9

Page 10: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 3: MSUD DOS AttackTop Hosts

10

Page 11: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Case 3: MSUD DOS AttackTop ASs

11

Page 12: NetVizura A network traffic analysis tool. Agenda Why NetVizura is needed How NetVizura works Where NetVizura is deployed Use cases

Questions?

12