{"id":37189,"date":"2019-10-31T22:16:15","date_gmt":"2019-10-31T19:16:15","guid":{"rendered":"https:\/\/prohoster.info\/blog\/setevoj-monitoring-i-vyyavleniya-anomalnoj-setevoj-aktivnosti-s-pomoshhyu-reshenij-flowmon-networks\/"},"modified":"2019-10-31T22:16:15","modified_gmt":"2019-10-31T19:16:15","slug":"setevoj-monitoring-i-vyyavleniya-anomalnoj-setevoj-aktivnosti-s-pomoshhyu-reshenij-flowmon-networks","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/setevoj-monitoring-i-vyyavleniya-anomalnoj-setevoj-aktivnosti-s-pomoshhyu-reshenij-flowmon-networks","title":{"rendered":"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/8509341060b74259e9383af1b28c1e59.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nRecently, there has been a wealth of material available online regarding <b>traffic analysis at the network perimeter.<\/b>However, everyone seems to completely overlook <b>local traffic analysis,<\/b>which is equally important. This article is dedicated to this topic. Using an example from <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/katalog\/flowmon\">Flowmon Networks,<\/a><\/noindex> we will revisit the good old Netflow (and its alternatives), explore interesting cases, possible anomalies in the network, and learn about the benefits of a solution where <b>the entire network operates as a single sensor.<\/b>Most importantly \u2014 conducting such a local traffic analysis can be completely free under a trial license (<b>45 days<\/b>). If you find this topic interesting, feel free to explore further. If you're lazy to read, you can register for the <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/events\/vebinari_flowmon\">upcoming webinar,<\/a><\/noindex>where we will demonstrate everything and provide detailed explanations (you will also learn about the upcoming training for the product).<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>What is Flowmon Networks?<\/h3>\n<p>\nFirst and foremost, Flowmon is a European IT vendor. The company is Czech, headquartered in Brno (the issue of sanctions is not even a consideration). The company has been present in its current form in the market since 2007. Before that, it was known under the brand Invea-Tech. Thus, nearly 20 years have been spent on the development of products and solutions.<\/p>\n<p>Flowmon is positioned as a top-tier brand. It develops premium solutions for enterprise clients and is noted in Gartner's quadrants for Network Performance Monitoring and Diagnostics (NPMD). Interestingly, among all companies in the report, Flowmon is the only vendor recognized by Gartner as a provider of solutions for both network monitoring and information protection (Network Behavior Analysis). While it doesn't hold the top spot, it also doesn't cost as much as a Boeing wing.<\/p>\n<h3>What tasks can the product solve?<\/h3>\n<p>\nGlobally, the following set of tasks can be highlighted that are addressed by the company's products:<\/p>\n<ol>\n<li>increasing network stability and resource uptime by minimizing downtime and unavailability;<\/li>\n<li>enhancing overall network performance;<\/li>\n<li>improving the productivity of the administrative staff by utilizing:\n<ul>\n<li>modern tools for innovative network monitoring based on IP flow information;<\/li>\n<li> providing detailed analytics on the operation and state of the network \u2013 users and applications operating within the network, transmitted data, interacting resources, services, and nodes;<\/li>\n<li> responding to incidents before they occur, instead of after users and clients experience service loss;<\/li>\n<li> reducing the time and resources needed for network and IT infrastructure administration;<\/li>\n<li> simplifying troubleshooting tasks.<\/li>\n<\/ul>\n<\/li>\n<li>increasing the level of security for the network and the company's information resources by using non-signature technologies to detect abnormal and malicious network activity, as well as zero-day attacks;<\/li>\n<li>ensuring the required level of SLA for network applications and databases.<\/li>\n<\/ol>\n<p><\/p>\n<h3>The product portfolio of Flowmon Networks<\/h3>\n<p>\nNow let's take a closer look at the Flowmon Networks product portfolio and find out exactly what the company does. As many have guessed from the name, the main specialization is in solutions for flow monitoring, along with a number of additional modules that expand the basic functionality.<\/p>\n<p>In fact, Flowmon can be described as a one-product company, or rather \u2013 as having one solution. Let's figure out whether this is good or bad.<\/p>\n<p>The core of the system is the collector, responsible for gathering data across various flow protocols, such as <b>NetFlow v5\/v9, jFlow, sFlow, NetStream, IPFIX<\/b>\u2026 It is quite logical that for a company not affiliated with any network equipment manufacturers, it is important to offer the market a universal product that is not tied to any specific standard or protocol.<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/d8dddeaa90c8bc03b78282b7ca00ea86.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Flowmon Collector<\/i><\/p>\n<p>The collector is available as both a hardware server and a virtual machine (VMware, Hyper-V, KVM). By the way, the hardware platform is implemented on customized DELL servers, which automatically alleviates many warranty and RMA concerns. The only proprietary hardware components are the FPGA traffic capture boards developed by a subsidiary of Flowmon, allowing monitoring at speeds of up to 100 Gbps.<\/p>\n<p>But what to do if there is no way to generate quality flow on the existing network equipment? Or if the load on the equipment is too high? No problem:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/53dda0e4f42ddbf7a8add1064e0ab913.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Flowmon Prob<\/i><\/p>\n<p>In this case, Flowmon Networks offers its own probes (Flowmon Probe) that connect to the network via the switch's SPAN port or by using passive TAP splitters.<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/298507c4bcb3d562f9621ff59ee6018f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>SPAN (mirror port) and TAP deployment options<\/i><\/p>\n<p>In this scenario, the 'raw' traffic arriving at the Flowmon Probe is converted into an extended IPFIX format, containing more <b>240 metrics with information<\/b>. While the standard NetFlow protocol generated by network devices contains no more than 80 metrics. This provides visibility to protocols not only on the 3rd and 4th levels but also on the 7th level of the ISO OSI model. As a result, network administrators can monitor the functioning of such applications and protocols as email, HTTP, DNS, SMB...<\/p>\n<p>Conceptually, the logical architecture of the system looks as follows:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/273517a6aa47726fe51c498114908c14.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe central part of the entire Flowmon Networks 'ecosystem' is the Collector, which receives traffic from existing network equipment or its own probes (Probe). However, providing functionality exclusively for monitoring network traffic for an Enterprise solution would be too simplistic. Open Source solutions can also do this, albeit not with the same performance. The value of Flowmon lies in the additional modules that extend the basic functionality:<\/p>\n<ul>\n<li>module <b>Anomaly Detection Security<\/b> \u2013 detection of anomalous network activity, including 'zero-day' attacks, based on heuristic traffic analysis and a typical network profile;<\/li>\n<li>module <b>Application Performance Monitoring<\/b> \u2013 performance monitoring of network applications without installing 'agents' and impacting target systems;<\/li>\n<li>module <b>Traffic Recorder<\/b> \u2013 recording fragments of network traffic according to a predefined set of rules or triggered by the ADS module, for further troubleshooting and\/or investigation of security incidents;<\/li>\n<li>module <b>DDoS Protection<\/b> \u2013 perimeter network protection against volumetric denial of service attacks DoS\/DDoS, including application attacks (OSI L3\/L4\/L7).<\/li>\n<\/ul>\n<p>\nIn this article, we will explore how everything works live using the example of 2 modules \u2013 <b>Network Performance Monitoring and Diagnostics<\/b> and <b>Anomaly Detection Security<\/b>.<br \/>\nInput data:<\/p>\n<ul>\n<li>Lenovo RS 140 server with VMware 6.0 hypervisor;<\/li>\n<li>the Flowmon Collector virtual machine image, which can be <noindex><a rel=\"nofollow\" href=\"https:\/\/www.flowmon.com\/en\/download-free-trial\">downloaded here<\/a><\/noindex>;<\/li>\n<li>a pair of switches supporting flow protocols.<\/li>\n<\/ul>\n<p><\/p>\n<h3>Step 1. Installation of Flowmon Collector<\/h3>\n<p>\nDeploying a virtual machine on VMware occurs in a completely standard way from an OVF template. As a result, we get a virtual machine running CentOS with the necessary software ready for use. The resource requirements are quite reasonable:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/9ae1559b01c639763e0053ee1de120ca.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWe just need to perform the basic initialization with the command <b>sysconfig<\/b>:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/c65a47dfd025595f7256b1e30b941e42.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWe configure the IP on the management port, DNS, time, Hostname, and we can connect to the WEB interface.<\/p>\n<h3>Step 2. License Installation<\/h3>\n<p>\nA trial license for one and a half months is generated and downloaded along with the virtual machine image. It is uploaded via <b>Configuration Center -&gt; License<\/b>. As a result, we see:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/a5c1c99ad14cf4ca5dfb560d55fa369d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAll set. We can start working.<\/p>\n<h3>Step 3. Configuring the Receiver on the Collector<\/h3>\n<p>\nAt this stage, you need to determine how data will flow into the system from the sources. As mentioned earlier, this could be one of the flow protocols or a SPAN port on the switch.<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/3ff1c77a58c152314a1615dd98ca92ca.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIn our example, we will use data reception via the protocols <b>NetFlow v9 and IPFIX<\/b>. In this case, we specify the IP address of the Management interface as the target \u2013 <b>192.168.78.198<\/b>. Interfaces eth2 and eth3 (of the Monitoring interface type) are used to receive a copy of the 'raw' traffic from the switch's SPAN port. We will skip these; they are not relevant to our case.<br \/>\nNext, we check the collector port where the traffic should arrive.<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/31fff2f3bfef52b001edb39bdb3293f9.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIn our case, the collector is expecting traffic on port UDP\/2055.<\/p>\n<h3>Step 4. Configuring Network Equipment for Flow Export<\/h3>\n<p>\nConfiguring NetFlow on Cisco Systems equipment can be considered quite standard for any network administrator. For our example, we will choose something a bit more unusual, like the MikroTik RB2011UiAS-2HnD router. Surprisingly, this budget solution for small and home offices also supports NetFlow v5\/v9 and IPFIX protocols. In the settings, we specify the target (collector address 192.168.78.198 and port 2055):<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/3604b4c1c0b013a3822e99d97ab9e9cb.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAnd add all available metrics for export:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/f22fa921b4195b184e82c12a2b852f3c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAt this point, we can say that the basic configuration is complete. Let's check if traffic is being received in the system.<\/p>\n<h3>Step 5. Checking and Operating the Network Performance Monitoring and Diagnostics Module<\/h3>\n<p>\nYou can check for traffic from the source in the section <b>Flowmon Monitoring Center -&gt; Sources<\/b>:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/b167ac4ba70c07d9d0fb521a1cf1a7ea.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWe see that data is coming into the system. After some time, when the collector accumulates traffic, the widgets will start displaying information:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/8cee4912c371366ff30ff7597f87cabc.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe system is built on the drill down principle. This means that the user, upon selecting an interesting fragment on the schematic or chart, 'dives down' to the level of data depth that they need:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/1caa3b3c59dcd77210f690606a16740f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nRight down to information about each network connection and link:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/ef8c8f4d2df0ae65b94fcc3be058099b.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Step 6. Anomaly Detection Security Module<\/h3>\n<p>\nThis module can be considered one of the most interesting, thanks to the use of signature-less methods for detecting anomalies in network traffic and malicious network activity. However, it is not an equivalent to IDS\/IPS systems. Working with the module begins with its 'training'. For this, a special wizard specifies all the key components and services of the network, including:<\/p>\n<ul>\n<li>gateway addresses, DNS, DHCP, and NTP servers,<\/li>\n<li>addressing in user and server segments.<\/li>\n<\/ul>\n<p>\nAfter this, the system enters the training mode, which lasts on average from 2 weeks to 1 month. During this time, the system forms a baseline of traffic characteristic to our network. Simply put, the system studies:<\/p>\n<ul>\n<li>what behavior is typical for network nodes?<\/li>\n<li>what data volumes are usually transferred and considered normal for the network?<\/li>\n<li>what working times are standard for users?<\/li>\n<li>what applications are running on the network?<\/li>\n<li>and much more..<\/li>\n<\/ul>\n<p>\nAs a result, we obtain a tool that detects any anomalies in our network and deviations from typical behavior. Here are a couple of examples that the system can identify:<\/p>\n<ul>\n<li>the spread of new malware in the network, undetectable by antivirus signatures;<\/li>\n<li>the creation of DNS, ICMP, or other tunnels transmitting data bypassing the firewall;<\/li>\n<li>the appearance of a new computer in the network posing as a DHCP and\/or DNS server.<\/li>\n<\/ul>\n<p>\nLet's see how this looks in action. Once your system has been trained and established a traffic baseline for the network, it begins to detect incidents:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/e4d7d168716fc9f703dd9f14faf5816f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe module's main page features a timeline displaying detected incidents. In our example, we see a clear spike, roughly between 9 and 16 hours. We highlight it and take a closer look. <\/p>\n<p>Anomalous behavior from an attacker in the network is clearly evident. It all starts when a host with the address 192.168.3.225 begins horizontal scanning of the network on port 3389 (Microsoft RDP service) and identifies 14 potential 'victims':<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/5844fab428bd7adedbc694bf7dc7f19e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nand<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/566cb37c28eb803d404e06a8d61372c3.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe next recorded incident involves host 192.168.3.225 launching a brute-force attack to guess passwords on the RDP service (port 3389) on previously identified addresses:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/18c97646b3982c5a9db86901cae9f5a7.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAs a result of the attack, an SMTP anomaly was recorded on one of the compromised hosts. In other words, spam distribution began:<\/p>\n<p><img decoding=\"async\" alt=\"Network monitoring and detection of abnormal network activity using Flowmon Networks solutions\" src=\"\/wp-content\/uploads\/2019\/08\/fd1fce3c9bb23903a3c54d270924c5fe.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThis example serves as a clear demonstration of the capabilities of the Anomaly Detection Security system and module, in particular. You can judge the effectiveness for yourself. We conclude this functional overview of the solution here.<\/p>\n<h3>Conclusion<\/h3>\n<p>\nIn summary, what conclusions about Flowmon can we draw from the remaining evidence:<\/p>\n<ul>\n<li>Flowmon is a premium-level solution for corporate clients;<\/li>\n<li>thanks to its versatility and compatibility, data collection is available from any source: network equipment (Cisco, Juniper, HPE, Huawei\u2026) or our own probes (Flowmon Probe);<\/li>\n<li>the solution's scalability allows for extending system functionality by adding new modules, as well as improving performance through a flexible licensing approach;<\/li>\n<li>through the use of signature-less analysis technologies, the system can detect even unknown zero-day attacks that antivirus and IDS\/IPS systems are unaware of;<\/li>\n<li>thanks to complete 'transparency' in terms of installation and the system's presence on the network, the solution does not impact the operation of other nodes and components of your IT infrastructure;<\/li>\n<li>Flowmon is the only solution on the market that supports traffic monitoring at speeds of up to 100 Gbps;<\/li>\n<li>Flowmon is suitable for networks of any scale;<\/li>\n<li>it offers the best price\/functionality ratio among similar solutions.<\/li>\n<\/ul>\n<p>\nIn this review, we covered less than 10% of the overall functionality of the solution. In the next article, we will discuss the remaining modules of Flowmon Networks. Using the Application Performance Monitoring module as an example, we will show how business application administrators can ensure availability at the specified SLA level and diagnose problems as quickly as possible.<\/p>\n<p>We would also like to invite you to our webinar (09\/10\/2019) dedicated to the vendor Flowmon Networks solutions. For pre-registration, please <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/events\/vebinari_flowmon\">register here<\/a><\/noindex>.<br \/>\nThat's all for now, thank you for your interest!<\/p>\n<p class=\"for_users_only_msg\">Only registered users can participate in the survey. <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/auth\/login\/\">Please log in<\/a><\/noindex>, please.<\/p>\n<h2 class=\"default-block__polling-title\">Are you using NetFlow for network monitoring?<\/h2>\n<ul class=\"content-list content-list_polling\">\n<li class=\"content-list__item content-list__item_polling\">\n<p>                    Yes<\/p>\n<\/li>\n<li class=\"content-list__item content-list__item_polling\">\n<p>                    No, but I plan to<\/p>\n<\/li>\n<li class=\"content-list__item content-list__item_polling\">\n<p>                    No<\/p>\n<\/li>\n<\/ul>\n<p>    9 users voted. 3 users abstained.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/463625\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u0432\u0440\u0435\u043c\u044f \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442\u0435 \u043c\u043e\u0436\u043d\u043e \u043d\u0430\u0439\u0442\u0438 \u043e\u0433\u0440\u043e\u043c\u043d\u043e\u0435 \u043a\u043e\u043b-\u0432\u043e \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u043e\u0432 \u043f\u043e \u0442\u0435\u043c\u0435 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u043d\u0430 \u043f\u0435\u0440\u0438\u043c\u0435\u0442\u0440\u0435 \u0441\u0435\u0442\u0438. \u041f\u0440\u0438 \u044d\u0442\u043e\u043c \u0432\u0441\u0435 \u043f\u043e\u0447\u0435\u043c\u0443-\u0442\u043e \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u043d\u043e \u0437\u0430\u0431\u044b\u043b\u0438 \u043e\u0431 \u0430\u043d\u0430\u043b\u0438\u0437\u0435 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0435 \u043c\u0435\u043d\u0435\u0435 \u0432\u0430\u0436\u043d\u044b\u043c. \u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043a\u0430\u043a \u0440\u0430\u0437 \u0438 \u043f\u043e\u0441\u0435\u0449\u0435\u043d\u0430 \u044d\u0442\u043e\u0439 \u0442\u0435\u043c\u0435. \u041d\u0430 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 Flowmon Networks \u043c\u044b \u0432\u0441\u043f\u043e\u043c\u043d\u0438\u043c \u0441\u0442\u0430\u0440\u044b\u0439 \u0434\u043e\u0431\u0440\u044b\u0439 Netflow (\u0438 \u0435\u0433\u043e \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u044b), \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u0435 \u043a\u0435\u0439\u0441\u044b, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27883,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-37189","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\".\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/setevoj-monitoring-i-vyyavleniya-anomalnoj-setevoj-aktivnosti-s-pomoshhyu-reshenij-flowmon-networks\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0421\u0435\u0442\u0435\u0432\u043e\u0439 \u043c\u043e\u043d\u0438\u0442\u043e\u0440\u0438\u043d\u0433 \u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u043d\u043e\u043c\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0440\u0435\u0448\u0435\u043d\u0438\u0439 Flowmon Networks | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\".\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/setevoj-monitoring-i-vyyavleniya-anomalnoj-setevoj-aktivnosti-s-pomoshhyu-reshenij-flowmon-networks\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:16:15+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:16:15+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Network monitoring and detection of anomalous network activity using Flowmon Networks solutions | ProHoster","description":".","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/setevoj-monitoring-i-vyyavleniya-anomalnoj-setevoj-aktivnosti-s-pomoshhyu-reshenij-flowmon-networks","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0421\u0435\u0442\u0435\u0432\u043e\u0439 \u043c\u043e\u043d\u0438\u0442\u043e\u0440\u0438\u043d\u0433 \u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u043d\u043e\u043c\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0440\u0435\u0448\u0435\u043d\u0438\u0439 Flowmon Networks | ProHoster","og:description":".","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/setevoj-monitoring-i-vyyavleniya-anomalnoj-setevoj-aktivnosti-s-pomoshhyu-reshenij-flowmon-networks","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:16:15+00:00","article:modified_time":"2019-10-31T19:16:15+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37189","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 16:39:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:32:13","updated":"2026-01-23 16:39:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=37189"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37189\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/27883"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=37189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=37189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=37189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}