Any Tool to replace Peakflow CP

Hello,

Does anyone here have a suggestion for a tool to replace Peakflow CP from Arbor Networks?

Please if possible you would like hear some suggestions.

Thanks.

Aluísio da Silva
Coordenação de Planejamento e Engenharia
CTBC
(34) 3256-2471
(34) 9976-0471
www.ctbc.com.br

Esta mensagem,incluindo seus anexos,pode conter informação confidencial e/ou privilegiada,sendo de uso exclusivo dos destinatários. Seu conteúdo não deve ser revelado.Caso você não seja o destinatário autorizado a receber esta mensagem,não poderá usar,copiar ou divulgar as informações nela contidas ou tomar qualquer ação baseada nesse e-mail,por favor,comunique ao remetente e a elimine imediatamente.Não nos responsabilizamos por opiniões e/ou declarações veiculadas por e-mail não ficando obrigada ao cumprimento de qualquer condição constante deste instrumento.

This message,including its attachments,contains and/or may contain confidential and privileged information.If you are not the person authorized to receive this message,you may not use,copy or disclose the information contained therein or take any action based on this information.If this message is received by mistake,please notify the sender by immediately replying to this email and deleting its files.We appreciate your cooperation.

hi aluisio

Hello,

Does anyone here have a suggestion for a tool to replace Peakflow CP from Arbor Networks?

# for reference

Please if possible you would like hear some suggestions.

- sflow based
http://www.sflow.com/products/floodprotect.php
http://www.inmon.com/technology/sflowTools.php

http://www.packetdam.com

- netflow based
  ?cisco url?

http://nfdump.sourceforge.net
http://nfsen.sourceforge.net

- jflow based
  ?juniper?

magic pixie dust
alvin

Hello!

Thanks for recommendation, Alvin!

As author of FastNetMon I will be very glad to hear some feedback
about my tool and could help with configuration / development :slight_smile:

hi pavel

Thanks for recommendation, Alvin!

just "on the list of flow stuff to look at"
- opensource like fastnetmon is good for techies and solving problems
- commercial products may be what large corp purchasing folks like

i've looked into the flow based products and got more confused :slight_smile:

As author of FastNetMon I will be very glad to hear some feedback
about my tool and could help with configuration / development :slight_smile:

cool ...

i went googlin around and found some additional info for the url list

>
> hi aluisio
>
>> Hello,
>>
>> Does anyone here have a suggestion for a tool to replace Peakflow CP from Arbor Networks?
>
> # for reference
> DDoS Mitigation Software & Tools - Arbor DDoS Platform
>
>> Please if possible you would like hear some suggestions.
>
> - sflow based

- sflow based # trademark owned by inmon
sFlow Products @ sFlow.org == list of vendors and collectors

> http://www.sflow.com/products/floodprotect.php

their blog.sflow.com has lots of feedback and comparisons

> InMon: sFlow Toolkit

http://www.inmon.com/products

>
> DDoS Detection and Mitigation Software :: Andrisoft Wanguard
> GitHub - FastVPSEestiOu/fastnetmon: This is old freezed version! Please use https://github.com/pavel-odintsov/fastnetmon for actual but unstable code
> http://www.packetdam.com
> DDoS Attack Defense and Detection Coverage with DefenseFlow
>

- netflow based -- netflow prototcol superceded by IPFIX

http://www.openbsd.org/cgi-bin/man.cgi?query=pflow&sektion=4&manpath=OpenBSD+Current

one day, i'll go poke around at linux-based tools like openbsd's pflow

>
> http://nfdump.sourceforge.net
> http://nfsen.sourceforge.net
> http://sourceforge.net/projects/panoptis

- openflow based

> - jflow based

juniper.net/us/en/products-services/security/
  - still can't find the jflow info :frowning:

magic pixie dust
alvin

Thank you all for the comments.

Does anyone know about FlowTraq and DeepField tools?

Thanks.

Aluísio da Silva
Coordenação de Planejamento e Engenharia
CTBC
(34) 3256-2471
(34) 9976-0471
www.ctbc.com.br

-----Mensagem original-----

Hi Aluisio,

Have you had a look at Lancope's Stealthwatch?

If you go that route give a shout as we've written a bunch of scripts to
do things like scan detection and new service alerting.

Cheers,
Harry

Very Happy with Kentik Detect, highly recommend it.

www.kentik.com

Cheers, Chris

Could it be GovCloud?

See http://defensesystems.com/articles/2014/08/21/aws-govcloud-disa-security-approval.aspx

Tom