YAF: Yet Another Flowmeter
Chris Inacio <inacio@cert.org> Brian Trammell <trammell@tik.ee.ethz.ch>
Wednesday, November 10, 2010
YAF: Yet Another Flowmeter Chris Inacio <inacio@cert.org> - - PowerPoint PPT Presentation
YAF: Yet Another Flowmeter Chris Inacio <inacio@cert.org> Brian Trammell <trammell@tik.ee.ethz.ch> Wednesday, November 10, 2010 Yet Another Flowmeter Flowmeter What is flow Why do you want flow So why YAF
Chris Inacio <inacio@cert.org> Brian Trammell <trammell@tik.ee.ethz.ch>
Wednesday, November 10, 2010
flow
YAF
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
libpcap capture DAG capture dumpfile input
Napatech
capture de-encapsulation partial defrag decode & lookup flow modification flush & export frag table flow table IPFIX file IPFIX export
Wednesday, November 10, 2010
Message Header Set Header Set Record Record ... Record Set Header Set Record Record ... Record Set Header Set Record Record ... Record Set Header Set Record Record ... Record Set Header Template Template ID IE count Information Element Length Information Element Length ... ... Information Element Length Template Template ID IE count Information Element Length Information Element Length ... ... Information Element Length Template Template ID IE count Information Element Length Information Element Length ... ... Information Element Length
Wednesday, November 10, 2010
Set Header [2] Template [257] Template [258] Template [310] Template Set Message Set Header [257] Record Record Record Data Set Set Header [310] Record Record Record Data Set Set Header [258] Record Record Record Data Set Message
Wednesday, November 10, 2010
Packet Features Capture Type
Wednesday, November 10, 2010
Packet Features Capture Type
Wednesday, November 10, 2010
Packet Features Capture Type
Wednesday, November 10, 2010
Packet Features Capture Type
Wednesday, November 10, 2010
Wednesday, November 10, 2010
, SSH, SMTP , Gnutella, Yahoo Messenger, DNS, FTP , SSL/TLS, SLP , IMAP , IRC, RTSP , SIP , RSYNC, PPTP , NNTP , TFTP , Teredo, MySQL, POP3
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Internet
YAF / Capture Device
HTTP IPFIX mediator FTP SSH flow DNS X.509 SMTP IPFIX mediator DNS processor PCAP Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Wednesday, November 10, 2010
Packet Features Privacy Capture Type Packet Details Privacy
Wednesday, November 10, 2010
Packet Features Privacy Capture Type Packet Details Privacy
Wednesday, November 10, 2010