Simple implementation of Distributed NetFlow Analysis system with Ossim
In order to analyze the abnormal traffic of network, we must first understand the principle and characteristics of the abnormal traffic, and analyze the types, flow, consequence, data packet type, address, port and so on. Linux NetFlow Data Acquisition analysis tool for Nfdump, through the Nfsen, with the Web interface, but if you completely through the previous compilation and installation of the NetFlow collection analysis platform is very complex.
The following three images show the implementation of distributed NetFlow systems in Ossim systems.
650) this.width=650; "title=" 1-5.jpg "style=" Float:none "alt=" wkiol1akd9kzucsfaamjka9xuoy075.jpg "src=" http:/ S4.51cto.com/wyfs02/m02/79/2b/wkiol1akd9kzucsfaamjka9xuoy075.jpg "/>
650) this.width=650; "title=" 1-52.jpg "style=" Float:none "alt=" wkiol1akd9xithrpaamxlqce74k025.jpg "src=" http:/ S1.51cto.com/wyfs02/m00/79/2b/wkiol1akd9xithrpaamxlqce74k025.jpg "/>
650) this.width=650; "title=" 1-53.jpg "style=" Float:none "alt=" wkiom1akd7kqihv8aaibwncxofi899.jpg "src=" http:/ S2.51cto.com/wyfs02/m00/79/2d/wkiom1akd7kqihv8aaibwncxofi899.jpg "/>
How to easily set up the NetFlow, please refer to the "open source safe operation Dimensional plane Ossim best practices" book.
This article is from the "Lee Chenguang Original Technology blog" blog, please be sure to keep this source http://chenguang.blog.51cto.com/350944/1731536
Simple implementation of Distributed NetFlow Analysis system with Ossim