Use Cases for Visibility Solutions
What is Network Visibility?
Visibility is defined by Webster's dictionary as "the state of being easily seen" or "the degree of clearness." Network or application visibility refers to eliminating blind spots that obscure the ability to easily see (or quantitatively assess) what is happening in the network and/or applications within it. This visibility enables IT teams to quickly isolate security threats and resolve performance issues, ultimately ensuring the best experience for end users.
Another understanding is that it allows IT teams to monitor and optimize the network alongside applications and IT services. This is why network, application, and security visibility is absolutely essential for any IT organization.
The simplest way to achieve network visibility is to implement a visibility architecture, which represents a comprehensive end-to-end infrastructure that, in turn, provides visibility into the physical and virtual networks, applications, and security.
Laying the Foundation for Network Visibility
Once the visibility architecture is established, a multitude of use cases will become available. As shown below, the visibility architecture represents three fundamental levels of visibility: access level, management level, and monitoring level.

Using the elements shown, IT professionals can address various network and application issues. There are two categories of use cases:
- Core Visibility Solutions
- Complete Network Visibility
Core visibility solutions focus on network security, cost savings, and troubleshooting. These are three criteria that impact IT on a monthly, if not daily, basis. Complete network visibility is intended to provide a deeper understanding of blind spot areas, performance, and regulatory compliance.
What can you actually do with network visibility?
There are six distinct use cases for network visibility that can clearly demonstrate its value. These include:
— Enhanced Network Security
— Providing capabilities for cost containment and reduction
— Accelerating troubleshooting and enhancing network reliability
— Eliminating network blind spots
— Optimizing network and application performance
— Strengthening compliance with regulations
Below are some specific use cases.
Example #1 – Filtering data for security solutions that sit in-line increases the effectiveness of those solutions
The goal of this option is to use a Network Packet Broker (NPB) for filtering low-risk data (such as video and voice) to exclude it from checks by security measures (Intrusion Prevention Systems (IPS), Data Loss Prevention (DLP), Web Application Firewalls (WAF), etc.). This 'unintrusive' traffic can be identified and sent back to a by-pass switch and forwarded within the network. The advantage of this solution is that WAF or IPS do not have to waste CPU resources analyzing unnecessary data. If your network traffic contains a significant volume of this type, you can implement this feature and reduce the load on your security tools.

Companies have reported instances where up to 35% of low-risk network traffic was excluded from IPS checks. This automatically increases the effective bandwidth of IPS by 35%, meaning you can defer purchasing additional IPS or upgrading. We all know that network traffic is increasing, so at some point, you will need a more powerful IPS. It really comes down to whether you want to minimize costs or not.
Example #2 – Load balancing extends the lifespan of 1-10 Gbps devices in a 40 Gbps network
The second example of usage involves reducing the total cost of ownership of network equipment. This is achieved through the use of packet brokers (NPB) to balance traffic across security and monitoring tools. How can load balancing help most enterprises? First, an increase in network traffic is a very common occurrence. But what about monitoring the impact of bandwidth growth? For instance, if you upgrade the core network from 1 Gbps to 10 Gbps, you'll need 10 Gbps tools for proper monitoring. If you increase the speed to 40 Gbps or 100 Gbps, the selection of monitoring tools at such speeds will be much smaller, and their cost will be very high.
Packet brokers provide the necessary capabilities for aggregation and load balancing. For example, 40 Gbps traffic balancing allows you to distribute monitoring traffic among several 10 Gbps tools. After that, you can extend the lifespan of the 10 Gbps devices until there are enough funds to acquire more expensive tools capable of handling higher data transfer speeds.

Another example is consolidating tools in one place and providing them with the necessary data from the packet broker. Sometimes separate solutions are used, distributed across the network. Survey data from Enterprise Management Associates (EMA) shows that 32% of enterprise solutions are underutilized, meaning they operate at less than 50% capacity. Centralizing tools and load balancing allow you to pool resources and increase utilization while using fewer devices. You can often delay the acquisition of additional tools until utilization rates become sufficiently high.
Example #3 – troubleshooting to reduce/eliminate the need for obtaining Change Board permissions.
Once the visibility equipment (taps (TAPs), NPB, etc.) is installed in the network, you will rarely need to make changes to the network. This allows you to optimize certain troubleshooting processes for increased efficiency.
For example, after TAP is installed ('set it and forget it'), it passively forwards a copy of all traffic to the NPB. This offers a significant advantage as it eliminates much of the bureaucratic hurdles involved in obtaining approvals for network changes. If a packet broker is also installed, there will be instant access to almost all the data needed for troubleshooting.

If there is no need to make changes, the change approval stages can be skipped, and one can proceed directly to debugging. This new process greatly impacts the reduction of the mean time to repair (MTTR). Studies indicate that it is possible to reduce MTTR by up to 80%.
Example #4 – Application Intelligence, utilizing application filtering and data masking to enhance security effectiveness
What is Application Intelligence? This technology is available from the packet brokers (NPB) IXIA. It is an advanced capability that goes beyond level 2-4 packet filtering (OSI model) and transitions fully to level 7 (application level). The advantage is that data on user and application behavior and location can be generated and exported in any required format — raw packets, filtered packets, or NetFlow (IxFlow) information. IT departments can identify hidden network applications, mitigate network security threats, and reduce network downtime and/or enhance network performance. Distinctive characteristics of known and unknown applications can be identified, captured, and relayed to monitoring and security tools.

- identification of suspicious/unknown applications
- detection of suspicious behavior based on geolocation, for instance, a user from North Korea connecting to your FTP server and transmitting data
- decryption SSL for verification and analysis of potential threats
- analysis of application malfunctions
- analysis of traffic volume and growth for active resource management and expansion forecasting
- masking sensitive data (credit cards, credentials…) before transmission
The Visibility Intelligence functionality is available both in physical and virtual (Cloud Lens Private) IXIA (NPB) packet brokers, as well as in public clouds — Cloud Lens Public:

In addition to the standard features of NetStack, PacketStack, and AppStack:

Recently, functionality for security has also been added: SecureStack (for optimizing the processing of confidential traffic), MobileStack (for mobile operators), and TradeStack (for monitoring and filtering financial trading data):



Conclusions
Network visibility solutions are a powerful tool that can optimize the architecture of network monitoring and security, creating a fundamental basis for collecting and exchanging essential data.
Use cases allow for:
- providing access to specific necessary data as needed for diagnostics and troubleshooting
- adding/removing security and monitoring solutions both in-line and out-of-band
- reducing MTTR
- ensuring rapid response to issues
- conducting extensive threat analysis
- eliminating most bureaucratic approvals
- minimizing the financial impact of breaches by promptly connecting necessary solutions to the network and reducing MTTR
- cutting costs and labor for SPAN port configuration
Source: habr.com
