home.social

#netflow — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #netflow, aggregated by home.social.

fetched live
  1. Detect sudden NetFlow traffic spikes with nfdump. Aggregate 5-min windows from a collector, filter flows over 10 MB, group by source/dest IPs, and sort results. Nfdump reads binary records, applies BPF filters, and computes aggregates on the fly. Full snippet: #network #nfdump #netflow

    valtersit.com/vault/netflow-tr

  2. New open-source project: flowsimulator-go 🚦
    Simulates enterprise networks — topology, personas, ordered session chains (DNS→Kerberos→LDAP→SMB) — and exports NetFlow v5/v9, IPFIX & sFlow v5.

    ~30 built-in session templates, from https-web & backup-transfer to low-weight security scenarios. Deterministic seeds, single Go binary, MIT.

    forgejo.sabolowitsch.org/Stefa
    #golang #NetFlow #IPFIX #sFlow #observability #opensource #selfhosted

  3. От видимости сети до кибербезопасности: главный миф о сетевой телеметрии, который мешает раскрыть потенциал NetFlow

    Привет, Хабр! На связи Станислав Грибанов, я руководитель продукта NDR компании «Гарда», автор блога «Кибербезопасность и продуктовая экспертиза для бизнеса» . Сегодня хочу поговорить о пользе NetFlow и сетевой телеметрии для защиты сетей от хакерских атак. Тема эта не новая, но вокруг неё до сих пор существует множество противоречий. Сетевая телеметрия часто воспринимается как артефакт из мира сетевых инженеров, а не как серьёзный инструмент информационной безопасности. Как правило, это связано с ошибочным восприятием NGIPS-систем, как аналога NTA. В этом случае основной считается функциональность сигнатурного детектирования атак, которая требует для работы только сырой трафик. При этом методы поведенческого анализа, машинного обучения и других несигнатурных техник в таких системах являются комплиментарными и не формируют ядро детектирующей логики. Из-за подобного ошибочного восприятия на российском рынке сформировалось массовое заблуждение: для поиска угроз в сетевом трафике нужен только анализ сырого сетевого трафика, а телеметрия для этого не подходит. Под катом я расскажу, как можно детектировать угрозы на основе метаданных сетевого трафика без анализа payload, в частности, сетевой телеметрии.

    habr.com/ru/companies/garda/ar

    #ndr #nta #netflow #ipfix #ml #TI_feeds #анализ_сетевого_трафика #ngips #anomaly_detection

  4. DPI, ТСПУ и операторы: архитектура блокировки трафика в России

    Когда смотришь на блокировки трафика со стороны пользователя, картина выглядит противоречиво: один и тот же сервис в разных сетях работает по-разному — где-то не открывается вовсе, где-то нестабилен, а где-то продолжает частично функционировать. При этом известно, что управление ограничениями централизовано. Возникает естественный вопрос: если политика едина, почему результат отличается? Причина в том, что речь идёт не об одной точке контроля, а о распределённой системе, где итоговое поведение формируется на пересечении трёх слоёв: централизованного управления, DPI/ТСПУ как контура распознавания и сети оператора как среды исполнения. Именно эта многослойность и объясняет наблюдаемую неравномерность. Что происходит дальше?

    habr.com/ru/articles/1027012/

    #dpi #тспу #анализ_трафика #сетевые_технологии #netflow #маршрутизация #информационная_безопасность #ркн #роскомнадзор #блокировки

  5. Собираем NetFlow-статистику через eBPF: от физических серверов до K8s

    Привет, Хабр! Я работаю сетевым инженером в компании, которая занимается разработкой софта. В этой статье расскажу о том, как мы собираем статистику сетевого трафика, и о трудностях, с которыми столкнулись и успешно справились. Когда речь идёт о расследовании инцидентов, связанных с безопасностью своих ресурсов, «приблизительной» статистики недостаточно — нужны подробности. Однако, встроенные в сетевое оборудование решения (вроде sFlow/NetFlow) с этим, как правило, не справляются:

    habr.com/ru/articles/1015480/

    #ebpf #xdp #netflow

  6. running malcom but the old malcolm - need to image and install latest - sort of dread going from debian to ubuntu but if i image i can revert easily. maybe they figured out updating, i don't want github only updates.

    anyways it is a good one to offer vs say security onion - they use the same components mostly, suricata, zeek, elastic, maybe he has a live iso like last time.

    i think the reason to go to ubuntu is better newer drivers, bigger dev base? as long as it works - that is my concern, avoid dependency hell and breakage.

    it is good with managing all the containers and space for /datastore #sigs #hashes #dpi #netflow #ntop-ng #tcp-replay #binaries #hashcat

  7. running malcom but the old malcolm - need to image and install latest - sort of dread going from debian to ubuntu but if i image i can revert easily. maybe they figured out updating, i don't want github only updates.

    anyways it is a good one to offer vs say security onion - they use the same components mostly, suricata, zeek, elastic, maybe he has a live iso like last time.

    i think the reason to go to ubuntu is better newer drivers, bigger dev base? as long as it works - that is my concern, avoid dependency hell and breakage.

    it is good with managing all the containers and space for /datastore #sigs #hashes #dpi #netflow #ntop-ng #tcp-replay #binaries #hashcat

  8. Shiba Inu Records -131 Billion in 24 Hours: Negative Netflow Signals Growing

    misryoum.com/us/economy/shiba-

    SHIB exchange flow is hinting at another rallyShiba Inu OI flips positive with 2.24% surgeThe Shiba Inu exchange netflow has gone extremely negative despite the weak price trend, suggesting that retail and institutional traders are quietly accumulating the asset...

    #Shiba #Inu #Records #131 #Billion #Hours #Negative #Netflow #Signals #Growing #US_News_Hub #misryoum_com

  9. Yes, You Too Can Be An Evil Network Overlord - On The Cheap With OpenBSD, pflow And nfsen nxdomain.no/~peter/yes_you_too

    A story about network metadata and #openbsd, originally from 2014, good for reprising. See The Book of PF for more #nfsen #netflow #pflow #monitoring #networking #security #pf #packetfilter #bookofPF @nostarch

  10. Yes, You Too Can Be An Evil Network Overlord - On The Cheap With OpenBSD, pflow And nfsen nxdomain.no/~peter/yes_you_too

    A story about network metadata and #openbsd, originally from 2014, good for reprising. See The Book of PF for more #nfsen #netflow #pflow #monitoring #networking #security #pf #packetfilter #bookofPF @nostarch

  11. @da_667 i would say go for the standalonelib? this would be a nice switch to use when building, more info is better #ntop-ng #netflow #logs

    Using nDPI as a standalone library when building Suricata is a powerful way to transform it from a traditional signature-based IDS/IPS into a smarter, more context-aware network security monitoring system. The integration addresses several key limitations of Suricata by adding a dedicated, high-performance deep packet inspection (DPI) engine .

    The table below summarizes the core reasons for this integration.
    Reason Explanation Key Benefits
    Massively Expanded Protocol Coverage Suricata natively supports ~20 protocols, while nDPI recognizes 450+ (including Cloud, IoT, and OT protocols) . Enables visibility into a wider range of applications and potential threats that Suricata would otherwise miss .
    Enhanced Threat Detection Capabilities nDPI adds behavioral analysis and risk detection to Suricata's signature-based approach . Allows detection of anomalies like encrypted traffic on standard ports, self-signed certificates, and command-and-control (C2) channels hiding in plain sight .
    More Powerful and Precise Rules The plugin introduces new rule keywords: ndpi-protocol and ndpi-risk . Enables writing rules based on detected application (e.g., TLS.YouTube) or specific risk (e.g., NDPI_BINARY_APPLICATION_TRANSFER), significantly reducing false positives .
    Richer Contextual Metadata Suricata's logs (EVE JSON) can be augmented with protocol and metadata identified by nDPI . Provides security analysts with deeper insights for faster threat hunting and forensic analysis without needing full packet captures .
    🛠️ How to Integrate nDPI with Suricata

    nDPI is integrated as a plugin that is not built into Suricata by default. You need to explicitly enable it during compilation. The process, as outlined in the official Suricata documentation, involves two main steps :

    Build Suricata with nDPI Support: When configuring your Suricata build from source, you must use the --enable-ndpi flag and point to your nDPI source code.
    bash

    ./configure --enable-ndpi --with-ndpi=/path/to/your/nDPI/source

    Load the Plugin: After installation, you need to ensure Suricata loads the nDPI plugin by adding its path to the suricata.yaml configuration file.
    yaml

    plugins:
    - /usr/lib/suricata/ndpi.so

    By building Suricata with the standalone nDPI library, you are essentially giving it a "second opinion" on network traffic. nDPI handles the heavy lifting of identifying countless applications and their potential risks, which then feeds directly into Suricata's core engine for alerting and logging. This makes your network defense far more robust and intelligent.

    Would you like to see more detailed examples of Suricata rules that use the ndpi-protocol and ndpi-risk keywords?

  12. @da_667 i would say go for the standalonelib? this would be a nice switch to use when building, more info is better #ntop-ng #netflow #logs

    Using nDPI as a standalone library when building Suricata is a powerful way to transform it from a traditional signature-based IDS/IPS into a smarter, more context-aware network security monitoring system. The integration addresses several key limitations of Suricata by adding a dedicated, high-performance deep packet inspection (DPI) engine .

    The table below summarizes the core reasons for this integration.
    Reason Explanation Key Benefits
    Massively Expanded Protocol Coverage Suricata natively supports ~20 protocols, while nDPI recognizes 450+ (including Cloud, IoT, and OT protocols) . Enables visibility into a wider range of applications and potential threats that Suricata would otherwise miss .
    Enhanced Threat Detection Capabilities nDPI adds behavioral analysis and risk detection to Suricata's signature-based approach . Allows detection of anomalies like encrypted traffic on standard ports, self-signed certificates, and command-and-control (C2) channels hiding in plain sight .
    More Powerful and Precise Rules The plugin introduces new rule keywords: ndpi-protocol and ndpi-risk . Enables writing rules based on detected application (e.g., TLS.YouTube) or specific risk (e.g., NDPI_BINARY_APPLICATION_TRANSFER), significantly reducing false positives .
    Richer Contextual Metadata Suricata's logs (EVE JSON) can be augmented with protocol and metadata identified by nDPI . Provides security analysts with deeper insights for faster threat hunting and forensic analysis without needing full packet captures .
    🛠️ How to Integrate nDPI with Suricata

    nDPI is integrated as a plugin that is not built into Suricata by default. You need to explicitly enable it during compilation. The process, as outlined in the official Suricata documentation, involves two main steps :

    Build Suricata with nDPI Support: When configuring your Suricata build from source, you must use the --enable-ndpi flag and point to your nDPI source code.
    bash

    ./configure --enable-ndpi --with-ndpi=/path/to/your/nDPI/source

    Load the Plugin: After installation, you need to ensure Suricata loads the nDPI plugin by adding its path to the suricata.yaml configuration file.
    yaml

    plugins:
    - /usr/lib/suricata/ndpi.so

    By building Suricata with the standalone nDPI library, you are essentially giving it a "second opinion" on network traffic. nDPI handles the heavy lifting of identifying countless applications and their potential risks, which then feeds directly into Suricata's core engine for alerting and logging. This makes your network defense far more robust and intelligent.

    Would you like to see more detailed examples of Suricata rules that use the ndpi-protocol and ndpi-risk keywords?

  13. Эволюция сбора flow-статистики в Яндексе: архитектура, грабли и оптимизации

    Привет, Хабр! На связи Саша Лопинцев, SRE в группе разработки сетевой инфраструктуры и мониторинга Yandex Infrastructure. Я очень люблю мониторинг — а когда дело касается видимости сетевого трафика, нам не обойтись без анализа flow‑данных. Сегодня расскажу, как и почему мы переехали с устаревшего flow‑коллектора на GoFlow2, реализовали запись в БД и через etcd решили проблемы с шаблонами. Новая система обрабатывает 85 тысяч пакетов статистики в секунду, обеспечивает отказоустойчивость и помогает создавать отчёты. Если вам интересно узнать чуть больше об архитектуре, экспериментах, ошибках и решениях, полезных для инфраструктурного мониторинга в продакшн‑среде, читайте далее.

    habr.com/ru/companies/yandex/a

    #flowметрики #goflow #goflow2 #etcd #ipfix #sflow #netflow

  14. UNC3886 leveraged ORB infrastructure for stealthy telecom targeting.

    Per Cyber Security Agency of Singapore:
    • Zero-day firewall compromise
    • Rootkit persistence mechanisms
    • GOBRAT & TINYSHELL C2 nodes
    • ORB-tagged IP clustering in Singapore ASNs
    • NetFlow-confirmed router-to-ORB communications
    • Pre-positioned reconnaissance

    Attribution aligned with assessments from Mandiant linking activity to China-sponsored espionage.

    ORB networks blur the line between botnets and residential proxy ecosystems, increasing attribution friction and collateral risk.

    Defensive priorities:
    • Threat intel enrichment
    • Edge device patch enforcement
    • ASN anomaly detection
    • Zero-trust segmentation
    • IoT telemetry visibility

    How mature are ORB detection capabilities in your SOC?

    Engage below.

    Source: cyberpress.org/orb-networks-ma

    Follow @technadu for advanced threat analysis.

    #ThreatIntel #UNC3886 #ORBNetworks #IoTSecurity #ZeroDay #C2Infrastructure #NetFlow #TelecomSecurity #BlueTeam #ThreatHunting #APTActivity #CyberOperations #Infosec

  15. UNC3886 leveraged ORB infrastructure for stealthy telecom targeting.

    Per Cyber Security Agency of Singapore:
    • Zero-day firewall compromise
    • Rootkit persistence mechanisms
    • GOBRAT & TINYSHELL C2 nodes
    • ORB-tagged IP clustering in Singapore ASNs
    • NetFlow-confirmed router-to-ORB communications
    • Pre-positioned reconnaissance

    Attribution aligned with assessments from Mandiant linking activity to China-sponsored espionage.

    ORB networks blur the line between botnets and residential proxy ecosystems, increasing attribution friction and collateral risk.

    Defensive priorities:
    • Threat intel enrichment
    • Edge device patch enforcement
    • ASN anomaly detection
    • Zero-trust segmentation
    • IoT telemetry visibility

    How mature are ORB detection capabilities in your SOC?

    Engage below.

    Source: cyberpress.org/orb-networks-ma

    Follow @technadu for advanced threat analysis.

    #ThreatIntel #UNC3886 #ORBNetworks #IoTSecurity #ZeroDay #C2Infrastructure #NetFlow #TelecomSecurity #BlueTeam #ThreatHunting #APTActivity #CyberOperations #Infosec

  16. OH: „I mean that it’s generally bad idea to enable Netflix on switch“

    #BGP #Netflow #sflow #InternetLarry

  17. Hopefully soon I'll publish a new project to create #netflow infrastructure in Oracle cloud with "one" click

    By the moment I've completed the "single developer" use case but a "one click #kubernetes cluster" is in progress

  18. Обзор NetFlow-коллектора с визуализацией Akvorado: от развертывания до практического использования

    Akvorado — не просто инструмент для привлечения трафика, а современное и масштабируемое решение, которое преобразует сырые данные (NetFlow, sFlow) в понятную и наглядную информацию. В этой статье мы расскажем о каждом этапе работы с Akvorado: от архитектуры до нюансов развертывания, опираясь на наш опыт.

    habr.com/ru/companies/hostkey/

    #hostkey #netflow #sflow #ipfix #akvorado #clickhouse #kafka #docker #сетевой_мониторинг

  19. mannmann.

    ich möchte mit #netflow spielen. Mein #Mikrotik kann als Probe dienen, einen Collector gibs hier: github.com/synfinatic/netflow2… ein Frontend hier: hub.docker.com/r/ntop/ntopng.
    Nur funktioniert das nicht, startet man ntopng mit dem Parameter --community, dann tauchen keine Daten im Frontend auf.
    Ohne --community schon, mit einem Manko:

    Das ist dann eine Demo-Version, die 10 Minuten(!!!) funktioniert. Natürlich kann man Lizenzen kaufen: shop.ntop.org/

    Bis vor kurzem hat die Combo netflowng/ntop(community) wohl noch funktioniert, aber nun nicht mehr: github.com/synfinatic/netflow2…

    Ich verstehe, daß man für seine Arbeit bezahlt werden möchte. Aber das: Aus einer funktionierenden Version eine 10-minütige Demo zu machen: Nein, das finde ich uncool. Und die älteren Versionen, die vermutlich noch funktioniert haben, gibt es nicht mehr, es gibt nur noch latest.

    Und nun? Was mache ich nun, wenn ich doch einfach nur mal mit Netflow spielen will?

  20. mannmann.

    ich möchte mit #netflow spielen. Mein #Mikrotik kann als Probe dienen, einen Collector gibs hier: github.com/synfinatic/netflow2… ein Frontend hier: hub.docker.com/r/ntop/ntopng.
    Nur funktioniert das nicht, startet man ntopng mit dem Parameter --community, dann tauchen keine Daten im Frontend auf.
    Ohne --community schon, mit einem Manko:

    Das ist dann eine Demo-Version, die 10 Minuten(!!!) funktioniert. Natürlich kann man Lizenzen kaufen: shop.ntop.org/

    Bis vor kurzem hat die Combo netflowng/ntop(community) wohl noch funktioniert, aber nun nicht mehr: github.com/synfinatic/netflow2…

    Ich verstehe, daß man für seine Arbeit bezahlt werden möchte. Aber das: Aus einer funktionierenden Version eine 10-minütige Demo zu machen: Nein, das finde ich uncool. Und die älteren Versionen, die vermutlich noch funktioniert haben, gibt es nicht mehr, es gibt nur noch latest.

    Und nun? Was mache ich nun, wenn ich doch einfach nur mal mit Netflow spielen will?

  21. Анализируем сетевой трафик средних и крупных сетей с помощью Netflow/IPFIX/sFlow и боремся с DoS/DDoS с помощью BGP

    Не так давно мы выпустили новую версию open source xFlow-коллектора и анализатора xenoeye . Это неплохой повод попиариться. тем более что xFlow-коллекторами/анализаторами часто пользуются для анализа, мониторинга и борьбы с DoS/DDoS атаками, это сейчас очень актуально. Если совсем коротко - анализатор собирает xFlow (Netflow и некоторые родственные протоколы типа Jflow, IPFIX, sFlow), распределяет их по объектам мониторинга, экспортирует информацию в СУБД (в текущей версии PostgreSQL), и может быстро реагировать на всплески трафика выше порогов для детекции DoS/DDoS атак с помощью скользящих средних. Информацию из СУБД можно визуализировать разными способами - генерировать статические картинки и отчеты или показывать красивое в Grafana. Реагировать на всплески можно тоже по-разному - отправлять сообщения в мессенджер, писать данные об аномалиях в БД, анонсировать BGP Flowspec для подавления атак.

    habr.com/ru/articles/909132/

    #netflow #ipfix #sflow #postgresql #grafana #ddos #bgp_flowspec

  22. Scheinbar hatte iich mal mit #netflow gespielt 😀
    root@a:/var/cache/nfdump# rm *
    bash: /usr/bin/rm: Argument list too long
    root@a:/var/cache/nfdump# ls | wc -l
    178239
    root@a:/var/cache/nfdump# ls | xargs rm
    root@a:/var/cache/nfdump# ls | wc -l
    0
    root@a:/var/cache/nfdump#
  23. Scheinbar hatte iich mal mit #netflow gespielt 😀
    root@a:/var/cache/nfdump# rm *
    bash: /usr/bin/rm: Argument list too long
    root@a:/var/cache/nfdump# ls | wc -l
    178239
    root@a:/var/cache/nfdump# ls | xargs rm
    root@a:/var/cache/nfdump# ls | wc -l
    0
    root@a:/var/cache/nfdump#
  24. IPFIX с точки зрения информационной безопасности

    NetFlow и IPFIX – это протоколы для сбора и анализа сетевого трафика, используемые для мониторинга, обеспечения безопасности и оптимизации работы сети. Они позволяют собирать метаданные о передаваемых пакетах и анализировать их для выявления аномалий, диагностики проблем и повышения эффективности сети. Про диагностику и повышение эффективности сети написано немало, поэтому в этой статье я хочу рассмотреть основные поля IPFIX(но аналогичные поля есть и у Netflow и других x-Flow ) и как можно их использовать в реальной практике на благо информационной безопасности.

    habr.com/ru/articles/883932/

    #netflow #ipfix

  25. Замолвите словечко за akvorado

    Добрый день! Меня зовут Михолап Константин. Работаю в небольшом операторе связи инженером, а вот в каком уже поймете по AS и страничке в PeeringDB. В 2025-ом году никого уже не удивить наличием возможности визуализировать входящий трафик для разного рода ISP или ЦОД, поэтому возможно Вы уже слышали что-то про Akvorado. В рамках этой статьи познакомимся с адаптацией такого программного комплекса инструмента Akvorado . И так, Akvorado - это Netflow-коллектор с функциями визуализации собираемого трафика. К публике он вышел в 2022 году, о нем много кто слышал, я уверен. Были разные материалы например в linkmeup. Очень прост для установки, развертывания и возможно даже обслуживания (если вы чуть-чуть знаете Сlickhouse).

    habr.com/ru/articles/881180/

    #akvorado #netflow #opensource #bgp #ipfix #visualization

  26. NDR – следующий уровень развития сетевой безопасности

    Привет Хабр, меня зовут Станислав Грибанов, я руководитель продукта NDR группы компаний «Гарда». В информационной безопасности работаю с 2010 года, с 2017 года занимаюсь развитием продуктов для сетевой безопасности, автор блога «Кибербезопасность и продуктовая экспертиза для бизнеса» . Это вторая статья из цикла, в котором я помогаю разобраться, что скрывается за аббревиатурами IDS и NTA, NDR, SOAR, XDR и EDR. В первой статье я рассказал об IDS и переходном этапе в виде NTA. Закономерным этапом развития сетевой защиты стали системы класса NDR, и в этой статье я остановлюсь на особенностях работы технологии подробнее: рассмотрю ключевые проблемы детектирования и реагирования на киберугрозы, отличие NDR от систем сетевой безопасности на базе сигнатурного анализа. Статья будет полезна специалистам по информационной безопасности, инженерам сетевой безопасности, аналитикам и IT-руководителям, которые хотят глубже разобраться в различных технологиях обнаружения и предотвращения угроз. Кроме того, статья будет интересна тем, кто изучает современные подходы к защите и планирует внедрять NDR в инфраструктуру своей компании.

    habr.com/ru/companies/garda/ar

    #network_security #network_detection_and_response #network_trafic_analysis #machine_learning #ids #dpi #threat_intelligence #netflow #ndr #active_response

  27. За грань netflow: что получается, если отказаться от ограничений

    Здравствуй, Хабр! Уже как 4 года я веду свой небольшой pet-проект в области netflow и его практического применения, и вот сейчас решил поделиться своими результатами. Эта история началась снежным московским днём, когда один уважаемый коллега поделился следующий новостью: ребята прочитали научную публикацию , провели свои эксперименты и написали статью на Хабр . У обеих работ были схожие выводы: определённые вредоносные воздействия, такие как DDoS или сканирования, обнаруживаются с весьма высокой точностью, но что-то менее "грубое" обнаружить уже сложно. Ребята, благодарю вас, что вы мне рассказали про данные штуки! Это стало отправной точкой для моего исследования. Можно ли не поднимаясь выше транспортного уровня ЭМВОС по данным netflow в сетевом трафике обнаруживать работу определённого приложения, ВПО или применение инструментов redteam? Да, можно! Но есть нюансы. Что у меня получилось будет изложено в этой статье.

    habr.com/ru/articles/871960/

    #информационная_безопасность #netflow #машинное_обучение #обнаружение_атак #впо #malware

  28. Detection is easy. Устанавливаем Elastiflow для поиска угроз в сети

    Начнем серию статей под названием Detection is easy , посвященных Detection engineering (DE), о чем я пишу в одноименном Telegram-канале . Один из этапов DE - определение источников событий и организация их сбора. В этой статье мы рассмотрим установку Elastiflow — это мощное решение для обработки и визуализации сетевых данных, построенное на основе стека ELK (Elasticsearch, Logstash, Kibana). Elastiflow предоставляет возможность собирать, обрабатывать и анализировать данные из различных сетевых протоколов, таких как NetFlow, sFlow и IPFIX. Основное преимущество Elastiflow по сравнению с классическим ELK-стеком заключается в оптимизированном агенте сбора сетевой телеметрии, а также в наличии готовых дашбордов и визуализаций, которые упрощают анализ сетевого трафика. Изначально проект развивался на GitHub , однако разработчики перешли к коммерческому решению — flow-collector , который демонстрирует значительно более высокую производительность по сравнению с версией, доступной на GitHub. Более подробную информацию о различиях можно найти в документации . Политика лицензирования позволяет бесплатно использовать продукт, но если ты зарегистрируешься, то будет доступно порядка 480 полей и использование одного инстанса (4000 записей в секунду, без регистрации 500).

    habr.com/ru/articles/871898/

    #netflow #elastic #elastiflow #инцидент #обнаружение_атак #обнаружение_аномалий #компьютерная_безопасность #компьютерная_криминалистика #компьютерные_сети

  29. my network upgrade proposal was framed by cisa alerts and best practice guidelines but also praxis - hopefully - they are doing a huge remodel so tackling network issue is good to do at same time. praxis in form of malcolm which keeps it basic - pcaps are in pcaps folder.
    they have to get more input from stakeholders and also find out when fiber is available #network visibility #netflow #ntop-ng deb file #ndpi

  30. In this blog post, I dug into a recent BGP leak by Uztelecom (first reported by our friends at @qrator_labs) by looking at impacts in #BGP and #NetFlow.

    This is the first post in a series entitled Beyond Their Intended Scope — a nod to the definition of a leak from RFC7908.
    kentik.com/blog/beyond-their-i

  31. Is your network congested or in danger of becoming overloaded?

    In "Yes, You Too Can Be An Evil Network Overlord - On The Cheap With OpenBSD, pflow And nfsen" nxdomain.no/~peter/yes_you_too you may find hints on how to solve that problem. #AppFlow #netflow #metadata #networkmonitoring #pflow #Surveillance #OpenBSD #IPFIX #nfsen #monitoring #congestion

  32. U.S. Nuke Agency Buys #InternetBackbone Data
    Defense Threat Reduction Agency (#DTRA) has bought access to #netflow data. The tool covers more than 90% of the world's #internet data and can trace activity through virtual private networks. The tool “is capable of following communications between servers, even private servers,” which allows the agency to identify infrastructure used by malicious actors in the hope of preventing #nuclearproliferation and #nuclear #terrorism.
    404media.co/u-s-nuke-agency-bu

  33. Feature or bug?

    "it would take too long to get data from the NSA"

    Maybe they are not offering enough Danegeld.

    404media.co/u-s-nuke-agency-bu

    #NetFlow

  34. Can ISPs #NetFlow data be used to track traffic going through VPNs?

    @ivpn explains how netflow aggregation coupled with other pieces of the puzzle can affect your #privacy while using a #VPN.

    #privacymatters

    ivpn.net/privacy-guides/isp-ne

  35. I realized just now that the previous had an important reference that needed to be made trackerless, so "DDOS Bots Are People! (Or Manned By Some, At Least)" is now available as nxdomain.no/~peter/ddos-bots-a #UDP #OpenBSD #blacklists #blocklists #DNS #blackhole #routing #ethics #netflow #security #monitoring #PF #nfsen #DDOS #attack

  36. 📰 Article: US Gov Purchases ISP Netflow Data

    (quote in article, Team Cymru) "explicitly markets its product’s capability of being able to track traffic through virtual private networks (VPN).. show w/server traffic originates from"

    #VPN #News #Netflow #databrokers #surveillancecapitalism #ISP #privacy #infosec #cybersecurity #Tor #i2p #USA

    vice.com/en/article/dy3z9a/fbi

  37. Here is the FBI’s Contract to Buy Mass Internet Data

    The #FBI previously purchased access to "netflow" data, which a company called Team #Cymru obtains from ISPs. #TeamCymru then sells it to the government.
    #netflow

    vice.com/en/article/dy3z9a/fbi

  38. The FBI previously purchased access to "netflow" data, which a company called Team Cymru obtains from ISPs. Team Cymru then sells it to the government.
    vice.com/en/article/dy3z9a/fbi
    #netflow #CYBER #privacy #worldnews #worldprivacy #data #DataBrokers #teamcymru

  39. My network is getting hammered by SSH scanners lately. Possibly checking for CVE-2023-25136. The IP below has sent over 2k flows in a day and Greynoise tags it as an SSH Bruteforcer and worm.
    Another IP originating from Russia (92.63.197[.]82) has also sent just over 2k flows. Historical analysis shows it targeting previous SSH vulnerabilities.

    #cve_2023_25136 #SSH #Netflow #Firewalla #IPS #SignalsIntelligence #Vulnerability

  40. Netflowlabeler is a Python tool to add labels to NetFlow text files developed by @eldraco at @stratosphere. If you have a NetFlow text file (e.g.: Zeek) and you want to add labels to it, you can add the labels and conditions to a configuration file and use this tool to assign them.
    Repo: github.com/stratosphereips/net

    #cybersecurity #datascience #machinelearning #networksecurity #zeek #netflow #networksecurity #datalabels #tools