cloud aware network management

24
Cloud-Aware Network Management Alex Henthorn-Iwane VP Marketing Kentik Technologies [email protected]

Upload: alex-henthorn-iwane

Post on 12-Apr-2017

178 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Cloud Aware Network Management

Cloud-Aware Network Management

Alex Henthorn-IwaneVP MarketingKentik [email protected]

Page 2: Cloud Aware Network Management

The Cloud is a Digital Supply Chain

• SaaS,PaaS,IaaS aremajorsuppliersforyourusers

• Enterprisesareofferingmorecloud-basedservices• Mobileapps• E-commerce

• WhichfunctionanddependonWebAPIs• Maps,Search,Ads,etc.

• TheInternetistheglobalfreightroutingsystem• Mustbehighperforming

Page 3: Cloud Aware Network Management

Cloud-Aware Net Mgmt: Strategic Considerations

• Assuresdeliveryofperformanceanduserexperience• DealswithrealityofInternetsecurity

• ParticularlyDDoSbecauseitisasmuchanoperationalavailabilityissueasasecuritychallenge

• Leveragesredundancyviamulti-homingandCDNinfrastructure

Page 4: Cloud Aware Network Management

Cloud-Aware Net Mgmt: Tactics

• Collectdetailedtrafficflowinformation

• Instrumentkeynexusserverswithperformancemetricscollection

• Utilizeadvancedanalytics• Deploysynthetictestingto

understandavailability• Limitedrelianceontraditional

deeppacketcapturetechniques,whicharecumbersomeforcloudnetworking

Page 5: Cloud Aware Network Management

Elements of Cloud Network Management

• NetFlow,sFlow,IPFIXtrafficflowdataexport• Sampledflowsarefine

• PassiveBGPpeering• Cost-effectiveserver-side

networkinstrumentation• Granular,tune-ablealertsfor

anomalies&attacks• Deepanalyticalvisibility• Automatedremediation

Page 6: Cloud Aware Network Management

Monitoring Considerations

• Globalvisibility• Top-downvisibility• Fulldetailsfordrill-downs

• Morethanjustsummaries

• Notsiloed• Integratewithothertools,

dashboards,etc.• Data/viewseasilysharedwithmany

functionalteams

• Supportsfullyhybridenvironments

Page 7: Cloud Aware Network Management

Alerting Considerations

• Network-wide• Scalablewithdetail• Host-levelcapable• Dynamicanomalydetection

(self-learningwhatisnormalbehavior)

• Flexibleintegrationwithyourchoiceofnotificationaswellasautomatedremediation• E.g.DDoSscrubbers,load

balancers,networkorchestration• Alerting&detectionneedstobe

complementedbydeepanalytics

Page 8: Cloud Aware Network Management

Reality of Network Big Data

• Networkdataisbigdata• Commonplacetogeneratehundreds

ofmillionsofdatarecordsperday• Traditionalapproachesverylimited

• Onlyproducedroll-upsummaries• Okayfortop-levelviews• Useless forrealaction

• Compute/storagescalemeansbigdataanalyticsarenowrelevant

• RecentannouncementbyCiscoonTetrationAnalyticsismajorsignal

• KeyistogopastBIandhaveoperationalspeed

Page 9: Cloud Aware Network Management

Big Data Challenges for Network Analytics

• Ingestspeed• Latencytoquery• Timetoqueryresponse

• Pre-computedcubes• Onthefly

Page 10: Cloud Aware Network Management

Advanced (Big Data) Network Analytics

• Needtoenableengineerstoleveragetheirtechnicalandinstitutionalknowledgeeffectively

• Ad-hocqueriesacrossmassivedatasetsinatimelymanner

• Multi-dimensionalanalytics• Combineandvisualizemultiplefields• Likeamassivepivottable

• Complementedbyautomatedanalysesthatrevealcomplexrelationships• Practicallyspeaking,turninginsightful

ad-hocqueries intodashboards

Page 11: Cloud Aware Network Management

Cloud-Based Analytics

• SaaSnetworkmanagementisnowbecomingmorecommon• Bigdataapproaches:DIYorSaaS• Veryeasytoadopt,fasttimetovalue,butnotfeasibleforall

Page 12: Cloud Aware Network Management

ACaseStudy:AdvancedAnalyticsofaDDoSAttack

Page 13: Cloud Aware Network Management

Starting from Top-Level View

• SeeminglyNormalVariationsoverSeveralDays….?

Page 14: Cloud Aware Network Management

Geo-Based Analytics

• LookingatonlySRC=CN(China)

Page 15: Cloud Aware Network Management

A Closer Look

• ZoomingintimerangeonSecondSpike

Page 16: Cloud Aware Network Management

Checking Another Dimension

• NumberofUniqueSourceIPAddresses

Page 17: Cloud Aware Network Management

Where is the Traffic Going?

• Flipto:DestinationAddresses

Page 18: Cloud Aware Network Management

Pulling Back to Gauge the Situation

• LookingatallinboundtraffictothetargetvictimDest IP

Page 19: Cloud Aware Network Management

Narrowing in on the Actual Attack

• Attackdetailsbyprotocol

Page 20: Cloud Aware Network Management

The Finding: Multi-Layer Attack

• Multiplesimultaneousvectorsathand

Page 21: Cloud Aware Network Management

The Mitigation Plan

• FindingtheNecessaryDetailsforSettingFilterPolicies

Page 22: Cloud Aware Network Management

Case Example: Summary

- UnusualtrafficpatternsfromsuspectGeo- TurnedouttobeDNSAmplificationtargetingaspecificdest IP- Butmainattackwashidingotherattacks/exploits- Dataharvestedformitigation

- Timerequiredtocompletethisanalysis:3minutes!

Page 23: Cloud Aware Network Management

Closing Thoughts

• Cloudisn’tjustanexternalresource,it’sawayofbusiness

• Internettrafficshouldbemoretopofmind

• Summarylevelviewsareinsufficientandbehindthecurve

• BigdataanalyticsandSaaSnetworkmanagementtoolsarenow

WE HAVE MET THE CLOUD AND

HE IS US

Page 24: Cloud Aware Network Management

www.kentik.com

ThankYou!