Descriptions du produit

Présentation de l'éditeur

Unlike packet sniffers that require you to reproduce network problems in order to analyze them, flow analysis lets you turn back time as you analyze your network. You'll learn how to use open source software to build a flow-based network awareness system and how to use network analysis and auditing to address problems and improve network reliability. You'll also learn how to use a flow analysis system; collect flow records; view, filter, and report flows; present flow records graphically; and use flow records to proactively improve your network. Network Flow Analysis will show you how to:

  • Identify network, server, router, and firewall problems before they become critical
  • Find defective and misconfigured software
  • Quickly find virus-spewing machines, even if they're on a different continent
  • Determine whether your problem stems from the network or a server
  • Automatically graph the most useful data

And much more. Stop asking your users to reproduce problems. Network Flow Analysis gives you the tools and real-world examples you need to effectively analyze your network flow data. Now you can determine what the network problem is long before your customers report it, and you can make that silly phone stop ringing.

Détails sur le produit

  • Format : Format Kindle
  • Taille du fichier : 1160 KB
  • Nombre de pages de l'édition imprimée : 224 pages
  • Utilisation simultanée de l'appareil : Illimité
  • Editeur : No Starch Press; Édition : 1 (28 juin 2010)
  • Vendu par : Amazon Media EU S.à r.l.
  • Langue : Anglais
  • Synthèse vocale : Activée
  • X-Ray :
  • Word Wise: Non activé
  • Composition améliorée: Non activé
  • Moyenne des commentaires client : Soyez la première personne à écrire un commentaire sur cet article
  • Classement des meilleures ventes d'Amazon: n°312.602 dans la Boutique Kindle (Voir le Top 100 dans la Boutique Kindle)
  •  Voulez-vous faire un commentaire sur des images ou nous signaler un prix inférieur ?

Commentaires client les plus utiles sur (beta) HASH(0x90f94fa8) étoiles sur 5 15 commentaires
12 internautes sur 12 ont trouvé ce commentaire utile 
HASH(0x90e101bc) étoiles sur 5 An enjoyable technical read 26 juillet 2010
Par Justin Sherrill - Publié sur
Format: Broché
I had initially expected to read a sort of agglomeration of tips; tools like Cacti or Munin for monitoring hardware; Wireshark or tcpdump for monitoring traffic, and so on. Instead, it goes very specifically into Netflow. Producing Netflow data, saving it, and making sense of it are the majority of the book.

People administering any sort of larger network, usually as part of the day job, are the target audience. Netflow appears to be supported by many network equipment vendors, and software tools exist to read it on *BSD.

(For the uninitiated, Netflow tracks network activity in terms of protocol, port, and so on - everything short of the actual data. It can describe what was happening at any point in time between hosts on a tracked network.)

As described in the book, it's useful for both tracking down active issues and for analyzing the health of a network that otherwise could be hidden by averaged graphs, or seen only by direct reads at the problem site. The book covers the protocol and various tools involved with it, and branches off into other related topics, like the use of gnuplot to create ad-hoc representations.

The book is enjoyable, with a touch of a conspiratorial Bastard Operator From Hell-like attitude between the author and the reader. It's a directed narrative going through install, analysis, and reporting, different enough from a man page review that there's value in proceeding from chapter to chapter. There's also enough detail in the center of the book that it can serve as a reference source for Netflow collector setup.

It was valuable enough that I found myself planning ways to implement this at my workplace. Remarkable, considering how dry network analysis can be.

(pasted from a review I wrote elsewhere)
4 internautes sur 4 ont trouvé ce commentaire utile 
HASH(0x90e10210) étoiles sur 5 Technical & Interesting Network Flow Analysis Reference 13 septembre 2010
Par Joshua Brower - Publié sur
Format: Broché
This is the second book of Lucas's that I have read. I read Absolute FreeBSD: The Complete Guide to FreeBSD, 2nd Edition, and thoroughly enjoyed it--So I went into this book with high expectations. Overall, I feel like this is a solid read for those network administrators that want to go deeper, and have the time to go deeper into network flow analyses.

NFA is a very technical book, which can make for a very boring read, but like Absolute FreeBSD, Lucas is able to maintain a light, interesting tone, even while discussing the configuration of gnuplot. (!)

From a technical perspective, NFA is very useful for getting your (open source) network flow analysis system up and going--But be aware that it will take time, especially if you want the flexibility of what FlowTracker/FlowGrapher can offer, versus the less flexible, but easier to use/learn CUFlow.

Lucas gives great practical examples of using flows to monitor & troubleshoot issues on your network. The examples are sprinkled through the book, and then a few case studies take up the last 7 pages of the book.

I found it interesting that the back cover claimed that you will learn how to:

-Identify network, server, router, and firewall problems before they become critical

-Find defective and mis-configured software

-Quickly find virus-spewing machines, even if they are on a different continent

These scenarios were covered, but in appallingly anemic sections--For instance, the "Quickly find virus-spewing machines, even if they are on a different continent" scenario was covered on 1 page. (186-187)

I guess I was thinking that since the above scenarios was a fairly large point in the description of the book, that they would be covered in a bit more detail.

One more nitpick: Lucas describes Conficker as both a Virus and a Worm--It is most definitely a worm, not a virus--There is a difference...

The above nitpicks are not enough to diminish the 5 star rating I am giving NFA: I found it to be a great addition to my reference bookshelf, and I'm sure it will be creased and dogeared as I attempt to implement my own NetFlow analysis system this next year.

-Josh Brower
3 internautes sur 3 ont trouvé ce commentaire utile 
HASH(0x90e10648) étoiles sur 5 Thin book on a thick subject, but it works well. 24 août 2010
Par Michael Ernest - Publié sur
Format: Broché
Network administration, never mind troubleshooting, is a dry, sometimes airless subject. As the cliche goes, computer networks may be more than the sum of their parts, but the only people who fully appreciate that have handled all the parts. Communication protocols, command protocols, wire protocols, internet protocols, data link management, router configuration, IP traffic management, firewall administration....Where mathematics or intricate programming techniques daze the disinclined mind, computer networking bludgeons it.

Lucas promotes his subject by motivating the imagination, not the intellect. As he writes in his introduction, "Network administrators all share an abiding and passionate desire for just one thing. We want our users to shut up." I for one can tell you where I was working and the problems I was dealing with when I first felt exactly that. And from that point on, the book flows neatly from one point to the next. The topic sequence, consistent tone and focus kept me engaged and confident that I could go as far as I'd like, with this book as a start.

To achieve that effect for me, a book has to look and feel manageable in a reasonable amount of time. Network Flow Analysis is about two hundred pages long, but it is hardly thin. The pace of discussion is deliberate but covers a lot of ground. As for continuity, I can't recall a passage that wasn't supported by earlier discussion or wasn't detailed soon after. Lucas narrates in a straightforward manner that does not succumb easily to distraction or concern for losing the reader. Where most authors tackle the subject with a compendium of summations or mostly-digested specifications, Lucas exhibits the guileless courage of someone who spends every day on a roof or under a sink. And he does something most network admin writers could learn to do for all our sakes: he uses a reference book for all the detail.

The only surprise I found in this book came in Chapter 8, "Ad Hoc Flow Visualization," where Lucas writes, "gnuplot ... has a notoriously steep learning curve and a reputation for complexity." Even though the rest of the paragraph softens this claim a bit, I bought and read a book on gnuplot to make sure I hadn't missed something.

Network Flow Analysis is not a book that would inspire a Dummies-identifying reader to have a go, I don't think. No such book will ever be written. But if troubleshooting the network becomes your job, and you need more than a kickstart, and you do want to shut people up, you need a friend. You could do far worse than start here.
3 internautes sur 3 ont trouvé ce commentaire utile 
HASH(0x90e10a14) étoiles sur 5 rollicking good read 17 mai 2012
Par shog - Publié sur
Format: Format Kindle Achat vérifié
Suprisingly lacking in dryness considering the subject matter. Author is a cunsummate smart-arse, highly conversant in the subject matter and often dropping interesting related facts, all the while flaunting a cocky sense of humor. A line in the first paragraph sums up the book:

"Network administrators all share an abiding and passionate desire for one thing: We want our users to shut up."

The guy backs his bark with bite. I feel he makes the reader feel like a plains indian if netflow were a buffalo. He will show you specifically how to go about setting up a netflow collector, how to install analysis tools, how to use them to determine all sorts of stuff, to how to use gnuplot to graph it. It covers host-level to bgp. I didn't know port numbers were used a different way for ICMP netflow packets, or that netflow v7 is actually useful for routers.

That said, the point of publishing is 2 years ago and I don't know how dated the material is. The author refers to very specific versions of software, which may have been perfectly useful on the day of publishing. That said, netflow itself does not change much (until IPFIX and IP6 roll out).

Oh, and this review is for the Kindle version. Somewhat perversely, I chose to run this entire book through text to speech while driving. While it was painful to hear a robotic man read out a full page of 5-tuple data, it worked out. Kudos to the publisher for not disabling text to speech.
2 internautes sur 2 ont trouvé ce commentaire utile 
HASH(0x90e109c0) étoiles sur 5 Damn Handy Book!! 20 février 2012
Par Christian Klaver - Publié sur
Format: Broché
As someone moving from strictly perimeter security to admin of a vast network, I needed a leg up to learning the intricacies of routing and Network Flow Analysis has turned out to be that book. Lucas clearly knows his subject far better than I could ever ask. The info and clear and *relevant*. That last part is critical, and the failing of many tech books I've read before this.

There are sections I don't happen to need (such as implementing netflow on the network in the first place, since my network already has this implemented) but the structure and lay-out of the book makes it easy to find and pull the info *I* need out of it. I've only had the book 48 hours or so, and it's already dominated the spot to the left of my PC at work.

Hide it, if you must, if you don't want to sully your reputation as THE alpha geek at work, but get it. Go get it now. There's plenty in here for both novice and guru alike.
