Network Flow Data Fusion
GeoSpatial and NetSpatial Data Enhancement
FloCon 2010 New Orleans, La Carter Bullard
QoSient, LLC
carter@qosient.com
1 Wednesday, January 20, 2010
Network Flow Data Fusion GeoSpatial and NetSpatial Data Enhancement - - PowerPoint PPT Presentation
Network Flow Data Fusion GeoSpatial and NetSpatial Data Enhancement FloCon 2010 New Orleans, La Carter Bullard QoSient, LLC carter@qosient.com Wednesday, January 20, 2010 1 Carter Bullard carter@qosient.com QoSient - Research and
QoSient, LLC
carter@qosient.com
1 Wednesday, January 20, 2010
– Naval Research Laboratory (NRL), GIG-EF, JCTD-LD, DISA, DoD Network Performance and Security Research
– Network Intrusion Research and Analysis – NAP Site Security Policy Development – Network Security Incident Coordinator
– Editor of ATM Forum Security Signaling Standards – IETF Working Group(s) Contributor – Internet2 Security WG – NANOG
2 Wednesday, January 20, 2010
This year's conference will focus on flow data analysis within the context of other data sources. Presenters are encouraged to consider how flow is a piece of the puzzle.
awareness of external attacks and insider abuse/misuse.
management, control and information assured.
3 Wednesday, January 20, 2010
Endsley, M. R. (1995b). Toward a theory of situation awareness in dynamic systems. Human Factors 37(1), 32-64.
volume of time and space
collection, combination, filtering, enhancement, processing, storage, retention and access.
relation to relevant goals and objectives.
4 Wednesday, January 20, 2010
5 Wednesday, January 20, 2010
6 Wednesday, January 20, 2010
Sometimes, ‘Where’ is the only criteria for comprehending that there is a problem.
Network flow data can be used in perception and comprehension of some of these very complex concepts, but the data needs to have some specific qualities in order to successively support ‘where’ functions.
7 Wednesday, January 20, 2010
8 Wednesday, January 20, 2010
9 Wednesday, January 20, 2010
10 Wednesday, January 20, 2010
11 Wednesday, January 20, 2010
12 Wednesday, January 20, 2010
13 Wednesday, January 20, 2010
14 Wednesday, January 20, 2010
anonymization.
15 Wednesday, January 20, 2010
16 Wednesday, January 20, 2010
BGP
Domain
Name Server
CNConnection Controller End Station Policy Server Call Controller Call Control Policy Control Connection Control Data Plane
ARP DNS STP OSPF
MPLS Network
RSVP-TE/LDP IS-IS-TE BGP
IS-IS-TE
OSPF
Root Servers
AAA
Station
17 Wednesday, January 20, 2010
BGP
Domain
Name Server
Connection Controller End Station Policy Server Call Controller Call Control Policy Control Connection Control Data Plane
ARP DNS STP OSPF
MPLS Network
RSVP-TE/LDP IS-IS-TE BGP
IS-IS-TE
OSPF
Root Servers
AAA
Station
CN
18 Wednesday, January 20, 2010
You Detect This?
Join Optimizations, Shortest Path Routing
Internet Iso-bar, Internet Distance Maps (IDMaps), Vivaldi, Dynamic Distance Maps (DDM), RON, Landmark Clustering, Dynamic Landmark Triangles, Netvigator
active RTT metrics such as ping() and traceroute(), differentiations involve sampling strategies and statistical analysis.
19 Wednesday, January 20, 2010
20 Wednesday, January 20, 2010
physical distance.
21 Wednesday, January 20, 2010
BGP
Domain
Name Server
Connection Controller End Station Policy Server Call Controller Call Control Policy Control Connection Control Data Plane
ARP DNS STP OSPF
MPLS Network
RSVP-TE/LDP IS-IS-TE BGP
IS-IS-TE
OSPF
Root Servers
AAA
Station
CN
22 Wednesday, January 20, 2010
JCTD-LD Multipoint Flow Data Monitoring
Large Data Joint Command Technical Demonstration
Naval Research Laboratory Oct 18, 2007 12:04:55 EDT 23 Wednesday, January 20, 2010
24 Wednesday, January 20, 2010
GeoSpatial Situational Awareness System
Mixed Black-box White-box Approach Local Area Network Implementation
Comprehensive Flow IS Black/Non-Visible Node White/Visible Node Data Plane Situational Awareness Data Flow Data Generation
25 Wednesday, January 20, 2010
GeoSpatial Situational Awareness System
Mixed Black-box White-box Approach Local Area Network Implementation
Comprehensive Flow IS Black/Non-Visible Node White/Visible Node Data Plane Situational Awareness Data Flow Data Generation
26 Wednesday, January 20, 2010
GeoSpatial Situational Awareness System
Mixed Black-box White-box Approach
Comprehensive Flow IS Black/Non-Visible Node White/Visible Node Data Plane Situational Awareness Data Flow Data Generation
27 Wednesday, January 20, 2010
GeoSpatial Situational Awareness System
Mixed Black-box White-box Approach
Comprehensive Flow IS Black/Non-Visible Node White/Visible Node Data Plane Situational Awareness Data Flow Data Generation
28 Wednesday, January 20, 2010
GeoSpatial Situational Awareness System
Mixed Black-box White-box Approach
Comprehensive Flow IS Black/Non-Visible Node White/Visible Node Data Plane Situational Awareness Data Flow Data Generation
29 Wednesday, January 20, 2010
802.11 a/b/g/n Bluetooth 30 Wednesday, January 20, 2010
a matter of inches
802.11 a/b/g/n Bluetooth 31 Wednesday, January 20, 2010
a matter of inches
802.11 a/b/g/n Bluetooth
rather surprising
32 Wednesday, January 20, 2010
a matter of inches
802.11 a/b/g/n Bluetooth
rather surprising
33 Wednesday, January 20, 2010
discrimination.
34 Wednesday, January 20, 2010
35 Wednesday, January 20, 2010