TRAFFIC ANALYSIS USING NETFLOW AND PYTHON


Abstract

This article presents an application that is used as NetFlow collector and analyzer. It is a console application created in Python language. A software analyzer detects and analyzes incoming NetFlow messages version 1 and 5 of devices that support them. The output file is a database of information and analysis of the overall UNIX time duration of reported traffic and analysis of NetFlow lifetime. The software is developed to work with Python version 3 and higher and is designed for the Windows operating system.


Keywords

IP networks; Computer languages; Software tools

Cisco Systems, Inc., Introduction to Cisco IOS NetFlow ¬– A Technical Overview. CISCO, 2012

IETF, Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of Flow Information. IETF Tools, 2013.

Cisco Systems, Inc.: NetFlow Services Solution Guide. http://www.cisco.com/c/en/us/td/docs/ios/solutions_docs/netflow/nfwhite.html [23.09.2016].

Plixer International, Inc., Flow Analytics, Plixer¬–Malware Incident Response, 2016.

Plixer International, Inc.: Top 5 Uses of NetFlow for Network Security. https://www.plixer.com/blog/netflow/top-5-uses-of-netflow-for-network-security/ [24.09.2016].

Network Security Research.: GDP¬–NetFlow Collector, BUT, 2015.

Plixer International, Inc., NetFlow packet Version 5 (V5), 2016.

Cole N.: An introduction to npyscreen. http://npyscreen.readthedocs.io/introduction.html [24.09.2016]

Python Software Foundation, Threading — Thread-based parallelism. Python 3.5.1 documentation, 1990-2016.

Oujezský V., Horváth T., Škorpil V.: Modeling Botnet C& C Traffic Lifespans from NetFlow Using Survival Analysis. In Proceedings of the 39th International Conference on Telecommunication and Signal Processing, TSP 2016. International Conference on Telecommunications and Signal Processing (TSP). Vienna, Austria, 2016, 50–55.

Download

Published : 2017-06-30


Oujezsky, V., & Horvath, T. (2017). TRAFFIC ANALYSIS USING NETFLOW AND PYTHON. Informatyka, Automatyka, Pomiary W Gospodarce I Ochronie Środowiska, 7(2), 5-7. https://doi.org/10.5604/01.3001.0010.4823

Vaclav Oujezsky  vaclav.oujezsky@phd.feec.vutbr.cz
Brno University of Technology, Department of Telecommunication  Czechia
Tomas Horvath 
Brno University of Technology, Department of Telecommunication  Czechia