You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 7 Next »

NetFlow data can be used to identify attacks on your network such as denial of service (DoS), viruses, and worms. Changes in network behavior is represented clearly with NetFlow data and understanding these deviations from normalcy can help in identifying harmful anomalies. An event or condition in the network that deviates from previously typical traffic patterns is considered an anomaly.

opFlow can detect anomalies by determining an average network usage baseline and comparing it with traffic of a suspected anomaly event. DoS attacks flood the network with packets from an untrusted source and usually it is a rather large packet size. Packet sizes are normally no larger than 150 bytes, creating an ingress policy for specific ports to discard packets larger than 150 bytes could prevent some DoS attacks from ever occurring.

NetFlow collects the Packet source, Port number, Destination Packet size, and Protocol number. Understanding what ports are commonly used on your network can help you in determining if abnormal activity is coming through. Using the Conversation Summary feature in opFlow allows for a detailed look into all conversations happening on your network. In Figure 1 below, you can see that the ports are filtered to only show Src Port 443. This packets are sorted to show packets received in descending order to see if the packet count is any higher than normal; this is why understanding what normal packet sizes are as well as their ports/sources on your network is important for any network engineer.

To view the Conversation Summary page navigate to menu -> Views -> Conversation Summary. The filter is added by simply typing the desired port in the box in the top right hand corner of the Conversation Summary page. The drop down menu to the right of the search box allows you to search for the specific Application, Source, Src Port, Destination, and Dst Port.


Figure 1 - Conversation Summary


  • No labels