Cloud-Scale BGP and NetFlow Analysis. Jim Frey, VP Product, Kentik Technologies December 15, 2015



Similar documents
The Kentik Data Engine

Application Performance Management (APM) Inspire Your Users With Every App Transaction. Anand Akela CA

End-to-End Network Centric Performance Management

Network-Wide Class of Service (CoS) Management with Route Analytics. Integrated Traffic and Routing Visibility for Effective CoS Delivery

Riverbed SteelCentral. Product Family Brochure

Riverbed SteelCentral. Product Family Brochure

WHITE PAPER SPLUNK SOFTWARE AS A SIEM

Elevating Data Center Performance Management

The Value of Flow Data for Peering Decisions

State of SIEM Challenges, Myths & technology Landscape 4/21/2013 1

Network Monitoring Comparison

Network Operations Analytics

How To Set Up Foglight Nms For A Proof Of Concept

Logentries Insights: The State of Log Management & Analytics for AWS

SolarWinds Network Performance Monitor powerful network fault & availabilty management

The Purview Solution Integration With Splunk

Whitepaper. 10 Metrics to Monitor in the LTE Network. blog.sevone.com

How To Get Started With Whatsup Gold

Splunk for Networking and SDN

Cheap and efficient anti-ddos solution

Viete, čo robia Vaši užívatelia na sieti? Roman Tuchyňa, CSA

SOLARWINDS NETWORK PERFORMANCE MONITOR

Regaining MPLS VPN WAN Visibility with Route Analytics. Seeing through the MPLS VPN Cloud

Unified network traffic monitoring for physical and VMware environments

CISCO INFORMATION TECHNOLOGY AT WORK CASE STUDY: CISCO IOS NETFLOW TECHNOLOGY

10 METRICS TO MONITOR IN THE LTE NETWORK. [ WhitePaper ]

INFRASTRUCTURE MONITORING:

EMC STORAGE RESOURCE MANAGEMENT SUITE

Managing LTE IP Transport Networks with Route Analytics

Decoding the Big Data Deluge a Virtual Approach. Dan Luongo, Global Lead, Field Solution Engineering Data Virtualization Business Unit, Cisco

Minder. simplifying IT. All-in-one solution to monitor Network, Server, Application & Log Data

Monitoring Log Management and Alerting

WhatsUp Gold 2016 Getting Started Guide

Essential Ingredients for Optimizing End User Experience Monitoring

Real-Time Traffic Engineering Management With Route Analytics

Intro to NSX. Network Virtualization VMware Inc. All rights reserved.

Network Monitoring. Easy, failsafe, and complete visibility of your network. Our customers have the same view as our NOC technicians.

Ipswitch WhatsUp Gold vs. Solarwinds Orion Comparing Product Offerings

RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL

Arbor s Solution for ISP

Server & Application Monitor

SolarWinds Network Performance Monitor

AccelOps NOC and SOC Analytics in a Single Pane of Glass Date: March 2016 Author: Tony Palmer, Senior ESG Lab Analyst

Measuring end-to-end application performance in an on-demand world. Shajeer Mohammed Enterprise Architect

Delivering actionable service knowledge

Network Security Monitoring: Looking Beyond the Network

Routing & Traffic Analysis for Converged Networks. Filling the Layer 3 Gap in VoIP Management

MSP. HOW MSPs Can Use Performance Monitoring to Create New Revenue Streams. [ WhitePaper ] Introduction

Flow Analysis Versus Packet Analysis. What Should You Choose?

Kaseya Traverse. Kaseya Product Brief. Predictive SLA Management and Monitoring. Kaseya Traverse. Service Containers and Views

Securing and Monitoring BYOD Networks using NetFlow

The Shortcut Guide To. Smart Network Management for the SMB. Chris Hampton. Network Management Software

THE 2014 THREAT DETECTION CHECKLIST. Six ways to tell a criminal from a customer.

Visualization, Management, and Control for Cisco IWAN

Network Metrics Content Pack for VMware vrealize Log Insight

SolarWinds Network Performance Monitor

whitepaper SolarWinds Integration with 3rd Party Products Overview

Service Description DDoS Mitigation Service

To Receive CPE Credit

How To Create Situational Awareness

One software solution to monitor your entire network, including devices, applications traffic and availability.

CA Opscenter: Delivering Exceptional Customer Experience in the Application Economy

7 Key Requirements for Distributed Network Monitoring

Automated Mitigation of the Largest and Smartest DDoS Attacks

STEALTHWATCH MANAGEMENT CONSOLE

IBM QRadar Security Intelligence Platform appliances

Cisco Remote Management Services for Security

BUILDING A SECURITY OPERATION CENTER (SOC) ACI-BIT Vancouver, BC. Los Angeles World Airports

NetFlow Tracker Overview. Mike McGrath x ccie CTO mike@crannog-software.com

MPLS WAN Explorer. Enterprise Network Management Visibility through the MPLS VPN Cloud

Who is Generating all This Traffic?

APIs The Next Hacker Target Or a Business and Security Opportunity?

Network Management Deployment Guide

Designing and Building an Open IT Operations Analytics (ITOA) Architecture

SecurityDAM On-demand, Cloud-based DDoS Mitigation

Redefine Network Visibility in the Data Center with the Cisco NetFlow Generation Appliance

QRadar Security Intelligence Platform Appliances

Scalable Extraction, Aggregation, and Response to Network Intelligence

Leveraging SDN and NFV in the WAN

The Time has come for A Single View of IT. Sridhar Iyengar March 2011

NetFlow/IPFIX Various Thoughts

Extreme Networks Purview Application Analytics Integration with VMware vrealize Log Insight

How To Make Data Streaming A Real Time Intelligence

Header 1. John T. Irwin Software Consulting Manager EMEA Managing End User Experience

Hillstone Intelligent Next Generation Firewall

Maintaining Non-Stop Services with Multi Layer Monitoring

Flow Analysis. Make A Right Policy for Your Network. GenieNRM

How To Sell Security Products To A Network Security Company

Comprehensive Security with Splunk and Cisco

SANS Top 20 Critical Controls for Effective Cyber Defense

F5 Intelligent DNS Scale. Philippe Bogaerts Senior Field Systems Engineer mailto: Mob.:

API Management: Powered by SOA Software Dedicated Cloud

Network Performance Management Solutions Architecture

Optimizing Service Levels in Public Cloud Deployments

Monitoring BGP and Route Leaks using OpenBMP and Apache Kafka

Transcription:

Cloud-Scale BGP and NetFlow Analysis Jim Frey, VP Product, Kentik Technologies December 15, 2015

Agenda Common NetOps Stress points Helpful Data Sets NetFlow, BGP Handling NetFlow and BGP at Cloud Scale Kentik s Approach Wrap-Up / Q&A 2

NetOps Stress Points: Needing Instant Answers Things You Need Answers to About/From Your Network Where in my network is the problem? Is this an attack or legitimate traffic? Does performance meet expectations? How should I allocate my resources in the future? $$$ X S S S R R S S S $$$ S S R R S S $$$

What We Hear. To Address These Questions, NetOps Needs: Accurate Visibility, Without Delay Relevant Alerts: No False Positives or Negatives Complete Data: Breadth + Depth Fast/Flexible Data Exploration Tools that don t suck (time or $$) 4

What Data Sets Can Help? And which ones can do the job cost effectively? 5

Primary Network Monitoring Data Choices Polled Stats Examples - SNMP, WMI Advantages - Ubiquitous - Good for monitoring device health/status/activity Disadvantages - No traffic detail - Typically n o frequen t th an every 5 minutes truly antireal-time Flow Records Examples - NetFlow, sflow, IPFIX Advantages - Details on traffic src/dest/content, etc. - Very cost effective Disadvantages - NRT (near real-time) at best - Incomplete app-layer detail - Limited performance metrics - Data volumes can be massive Packet Inspection Examples - Packets -> xflow - Long term stream-to-disk Advantages - Most complete app layer detail - True real-time (millisecond lvl) - Complete vendor independent Disadvantages - Expensive to deploy at scale - Requires network tap or SPAN - Packet captures can be massive 6

Secondary Network Monitoring Data Choices Log Records Examples - Syslog Advantages - Continuous/streaming - Unique, device-specific info - True real-time Disadvantages - No standards must have very flexible search/mapping tools - Data volumes can be massive Routing/Path Data Examples - OSPF, IGRP, BGP Advantages - Details on traffic paths and provider volumes - Insights into Internet factors Disadvantages - Address data only no awareness of traffic - Must peer with routers to get updates Synthetic Agents Examples - IP SLA, Independent test sw Advantages - Assess functions/services 24x7 - Provides both availability and performance measures Disadvantages - Deploying/maintaining enough agents to achieve full coverage - Only an approximation of real user experience (at best) 7

Key Assertion: Use Multiple Data Types for Best Results You never know which data set will present the specific insights you need The challenge (real magic) comes from correlating multiple datasets, i.e.: Behavioral observations with configuration changes Trends with underlying traffic details Routing data with traffic data 8

Why Correlate Routing Data with Traffic Data? For Providers Recognizing new service opportunities based on subscriber (and peer) behavior Optimizing peering relationships for cost control For Web Services / Commerce Recognizing where your customers are and how they reach you Managing peering relationships for best customer experience For Enterprise Assessing how your connectivity providers perform/compare Building Internet IQ how you connect/relate to the outside world 9

Cloud Scale for NetFlow and BGP: The Big Data Challenge Why can t we just use our existing tools? 10

Existing Tools: Falling Behind Network traffic has grown exponentially; Legacy tools/tech haven t kept pace. Result? Fragmented tools, visibility gaps, unanswered questions. Cloud, SaaS, Big Data 10G 100G 1G 10M 100M

Why Big Data? - Network Monitoring Data IS Big Data - Meets Volume/Variety/Velocity Test - Billions of records/day (millions/second) - Big Data architectures are considered best practices today for open/flexible correlation, analytics 12

Why Big Data? - Network Monitoring Data IS Big Data - Meets Volume/Variety/Velocity Test - Billions of records/day (millions/second) - Big Data architectures are considered best practices today for open/flexible correlation, analytics Specific Challenges For NetFlow + BGP Existing solutions shortfalls: - Flexibility for moving between viewpoints and into full details - Data Completeness due to reliance on summarized/aggregated flow data - Speed: Generating new analysis in a timely manner 13

How to Get/Use Big Data Approach? 14

How to Get/Use Big Data Approach? 1. BYO Build Your Own Pick back end & reporting/analysis tools (open source = free?) Procure operating platforms (hard, virtual, or cloud servers = $$) Integrate, add data sources, and get it up and running (dev = $$) Keep it up and running (ops/admin = $$) 15

How to Get/Use Big Data Approach? 1. BYO Build Your Own Pick back end & reporting/analysis tools (open source = free?) Procure operating platforms (hard, virtual, or cloud servers = $$) Integrate, add data sources, and get it up and running (dev = $$) Keep it up and running (ops/admin = $$) 2. Let SOMEONE ELSE build/optimize/operate Subscribe to SaaS (ops $$) Just Send Your Data and enjoy the ride! 16

Kentik s Answer How we address the Big Data challenge to meet the needs of Network Operators now 17

Kentik Detect: the first and only SaaS Solution For Network Ops Management & Visibility at Terabit Scale Web Portal Real-time & historical queries S S S R R NetFlow/ sflow/ipfix SNMP BGP Kentik Data Engine Alerts E-mail / Syslog / JSON Open API SQL / RESTful The Network is the Sensor Big Data Network Telemetry Platform Analyze & Take Action CLOUD- BASED REAL- TIME MULTI- TENANT OPEN GLOBAL

What s Behind the Kentik Data Engine Multi-tiered/Clustered for Scale / Load Balancing / HA, Hosted by Kentik INGEST CLUSTER DATA STORAGE CLUSTER CLIENTS POSTGRES SERVERS NetFlow SNMP BGP SQL N M Optimized for Massive Data Ingest & Rapid Query Response

Kentik Portal Dashboard 20

Top Traffic Flows 21

Traffic by Source Geography 22

AS Path Changes 23

AS Top Talkers and Drill Down Options 24

Peering Analytics: ASN by Dest Country Paths 25

Peering Analytics: Traffic by BGP Paths 26

Peering Analytics: Traffic by Origin AS ( Last Hop ) 27

Peering Analytics: Traffic by Transit AS 28

Key Takeaways: Cloud Scale NetFlow + BGP Why You Need It - Clear Insight into external/internet network traffic behaviors - Improved customer/subscriber engagement - Reduced network operating costs Technical Path to Success - This is a big data problem, requiring high capacity/speed for data management, correlation, exploration, and analytics - SaaS solutions are a fully viable option

Network Intelligence at Terabit Scale Thank You! Jim Frey VP Product Kentik Technologies jfrey@kentik.com @jfrey80