CARVIEW |
Network Flow Analysis
- By
- Michael W. Lucas
- Publisher:
- No Starch Press
- Released:
- June 2010
- Pages:
- 224
Network flow analysis is the art of studying the traffic on a computer network. Understanding the ways to export flow and collect and analyze data separates good network administrators from great ones. The detailed instructions in Network Flow Analysis teach the busy network administrator how to build every component of a flow-based network awareness system and how network analysis and auditing can help address problems and improve network reliability.
You know that servers have log files and performance measuring tools and that traditional network devices have LEDs that blink when a port does something. You may have tools that tell you how busy an interface is, but mostly a network device is a black box. Network Flow Analysis opens that black box, demonstrating how to use industry-standard software and your existing hardware to assess, analyze, and debug your network.
Unlike packet sniffers that require you to reproduce network problems in order to analyze them, flow analysis lets you turn back time as you analyze your network. You'll learn how to use open source software to build a flow-based network awareness system and how to use network analysis and auditing to address problems and improve network reliability. You'll also learn how to use a flow analysis system; collect flow records; view, filter, and report flows; present flow records graphically; and use flow records to proactively improve your network. Network Flow Analysis will show you how to:
- Identify network, server, router, and firewall problems before they become critical
- Find defective and misconfigured software
- Quickly find virus-spewing machines, even if they're on a different continent
- Determine whether your problem stems from the network or a server
- Automatically graph the most useful data
And much more. Stop asking your users to reproduce problems. Network Flow Analysis gives you the tools and real-world examples you need to effectively analyze your network flow data. Now you can determine what the network problem is long before your customers report it, and you can make that silly phone stop ringing.
-
Chapter 1 FLOW FUNDAMENTALS
-
What Is a Flow?
-
Flow System Architecture
-
The History of Network Flow
-
Flows in the Real World
-
Flow Export and Timeouts
-
Packet-Sampled Flows
-
-
Chapter 2 COLLECTORS AND SENSORS
-
Collector Considerations
-
Sensor Considerations
-
Implementing the Collector
-
Installing Flow-tools
-
Running flow-capture
-
How Many Collectors?
-
Collector Log Files
-
Collector Troubleshooting
-
Configuring Hardware Flow Sensors
-
Configuring Software Flow Sensors
-
The Sensor: softflowd
-
-
Chapter 3 VIEWING FLOWS
-
Using flow-print
-
Setting flow-print Formats with -f
-
TCP Control Bits and Flow Records
-
ICMP Types and Codes and Flow Records
-
-
Chapter 4 FILTERING FLOWS
-
Filter Fundamentals
-
Useful Primitives
-
Filter Match Statements
-
Using Multiple Filters
-
Logical Operators in Filter Definitions
-
Filters and Variables
-
-
Chapter 5 REPORTING AND FOLLOW-UP ANALYSIS
-
Default Report
-
Modifying the Default Report
-
Analyzing Individual Flows from Reports
-
Other Report Customizations
-
Useful Report Types
-
Customizing Reports
-
-
Chapter 6 PERL, FLOWSCAN, AND CFLOW.PM
-
Installing Cflow.pm
-
flowdumper and Full Flow Information
-
FlowScan and CUFlow
-
FlowScan Prerequisites
-
Installing FlowScan and CUFlow
-
Flow Record Splitting and CUFlow
-
Using Cflow.pm
-
-
Chapter 7 FLOWVIEWER
-
FlowTracker and FlowGrapher vs. CUFlow
-
FlowViewer Security
-
Installing FlowViewer
-
Configuring FlowViewer
-
Using FlowViewer
-
FlowGrapher
-
FlowTracker
-
Interface Names and FlowViewer
-
-
Chapter 8 AD HOC FLOW VISUALIZATION
-
gnuplot 101
-
Time-Series Example: Bandwidth
-
Automating Graph Production
-
Comparison Graphs
-
-
Chapter 9 EDGES AND ANALYSIS
-
NetFlow v9
-
sFlow
-
Problem Solving with Flow Data
-
Afterword
-
-
UPDATES

- Title:
- Network Flow Analysis
- By:
- Michael W. Lucas
- Publisher:
- No Starch Press
- Formats:
-
- Ebook
- Safari Books Online
- Print Release:
- June 2010
- Ebook Release:
- July 2010
- Pages:
- 224
- Print ISBN:
- 978-1-59327-203-6
- | ISBN 10:
- 1-59327-203-0
- Ebook ISBN:
- 978-1-59327-300-2
- | ISBN 10:
- 1-59327-300-2
-
Michael W. Lucas
Michael W. Lucas is a network/security engineer who keeps getting stuck with network problems nobody else wants to touch. He is the author of the critically acclaimed Absolute FreeBSD, Absolute OpenBSD, Cisco Routers for the Desperate, and PGP & GPG, all from No Starch Press.
![]() ©2010, O'Reilly Media, Inc. (707) 827-7000 / (800) 998-9938 All trademarks and registered trademarks appearing on oreilly.com are the property of their respective owners. |
About O'Reilly
Academic Solutions Authors Contacts Customer Service Jobs Newsletters O'Reilly Labs Press Room Privacy Policy RSS Feeds Terms of Service User Groups Writing for O'Reilly |
Content Archive Business Technology Computer Technology Microsoft Mobile Network Operating System Digital Photography Programming Software Web Web Design |
More O'Reilly Sites
O'Reilly Radar Ignite Tools of Change for Publishing Digital Media Inside iPhone makezine.com craftzine.com hackszine.com perl.com xml.com Partner Sites InsideRIA java.net O'Reilly Insights on Forbes.com |