Welcome to the NetFlow Auditor Blog

NetFlow Auditor Team

Find me on:

Recent Posts

Integrated Cyber Network Intelligence : Why would you need Granular Network Intelligence?

Posted by NetFlow Auditor Team on Apr 4, 2017 7:30:00 AM

“Advanced targeted attacks are set to render prevention-centric security strategies obsolete and that information must become the focal point for our information security strategies.” (Gartner)

In this webinar we take a look at the internal and external threat networks pervasive in todays enterprise and explore why organizations need granular network intelligence.

 

Read More

Topics: Cyber Security

End Point Threat Detection Using NetFlow Analytics

Posted by NetFlow Auditor Team on Feb 21, 2017 8:47:00 AM
Read More

Topics: NetFlow, Cyber Security, Threat Detection

NetFlow for Advanced Threat Detection

Posted by NetFlow Auditor Team on Nov 24, 2015 7:00:00 AM

Businesses spend a lot of effort and expense setting up their networks to provide all the data flows and applications necessary so that their employees are very productive in performing their tasks.

These networks are vital assets to the business and require absolute protection against unauthorized access, malicious programs, and degradation of performance of the network. It is no longer enough to only use Anti-Virus applications.

By the time malware is detected and those signatures added to the antiviral definitions, access is obtained and havoc wreaked or the malware is buried itself inside the network and is obtaining data and passwords for later exploitation.

 

An article by Drew Robb in eSecurity Planet on September 3, 2015 (http://www.esecurityplanet.com/network-security/advanced-threat-detection-buying-guide-1.html) cited the Verizon 2015 Data Breach Investigations Report where 70 respondents reported over 80,000 security incidents which led to more than 2000 serious breaches in one year.

Read More

Topics: NetFlow

What is NetFlow & How Can Organizations Leverage It?

Posted by NetFlow Auditor Team on Nov 20, 2015 7:00:00 AM
NetFlow is a feature originally introduced on Cisco devices (but now generally available on many vendor devices) which provides the ability for an organization to monitor and collect IP network traffic entering or exiting an interface.
 
Through analysis of the data provided by NetFlow, a network administrator is able to detect things such as the source and destination of traffic, class of service, and the causes of congestion on the network.
 

NetFlow is designed to be utilized either from the software built into a router/switch or from external probes.

The purpose of NetFlow is to provide an organization with information about network traffic flow, both into and out of the device, by analyzing the first packet of a flow and using that packet as the standard for the rest of the flow. It has two variants which are designed to allow for more flexibility when it comes to implementing NetFlow on a network.

 

NetFlow was originally developed by Cisco around 1990 as a packet switching technology for Cisco routers and implemented in IOS 11.x.

The concept was that instead of having to inspect each packet in a “flow”, the device need only to inspect the first packet and create a “NetFlow switching record” or alternatively named “route cache record”. 

Read More

Topics: NetFlow

Two Ways Networks Are Transformed By NetFlow

Posted by NetFlow Auditor Team on Oct 20, 2015 6:39:22 AM

According an article in techtarget.com "Your routers and switches can yield a mother lode of information about your network--if you know where to dig."  The article goes on to say that excavating and searching through endless traffic data and logs manufactured by your network system is a lot like mining for gold, and punching random holes to look for a few nuggets of information isn't very efficient. Your search will be much more fruitful if you know where to look and what it will look like. Fortunately, the data generated by a NetFlow traffic reporting protocol yields specific information and you can easily sort, view and analyze the information into what you want to use or need.

Read More

Topics: NetFlow