NetFlow and sFlow Configuration Guide on Cisco 8000 Series Routers, Cisco IOS XR Releases

PDF

NetFlow and sFlow Configuration Guide on Cisco 8000 Series Routers, Cisco IOS XR Releases

Use Case: NetFlow and sFlow in Action

Let’s explore a use case and learn how to deploy NetFlow and sFlow protocols to monitor and curb malicious attack on the network via a use case.


Here's a hypothetical use case illustrating a bad actor (attacker) sending malicious traffic and the network getting compromised:

Figure 1. Malicious activity in a network
Attacker compromises network to retrieve critical data
  • Attack entry point—An Enterprise becomes the target of a cyber attack. The attacker employs various tactics to gain unauthorized initial access to the network.

  • Generate malicious traffic— After the attacker identifies vulnerable devices as potential targets, they compromise a host and start generating malicious traffic and potentially launch DDoS attacks, to steal sensitive data, or take control of the network using these compromised machines as a platform.

  • Breach data—The malicious traffic triggers a series of attacks within the network. With access to sensitive data, the attacker attempts retrieving critical data from the compromised network.

With this context, lets explore these two scenarios: