flowchart LR
A[Network Traffic] --> B{Flow Technology}
B --> C[NetFlow]
B --> D[sFlow]
B --> E[IPFIX]
%% NetFlow
C --> C1[Developed by Cisco]
C --> C2[Flow-based Monitoring]
C --> C3[L3/L4 Metadata Export]
C --> C4[Traffic Analysis]
C --> C5[Capacity Planning]
%% sFlow
D --> D1[Developed by InMon]
D --> D2[Packet Sampling]
D --> D3[Interface Statistics]
D --> D4[High-Speed Networks]
D --> D5[Low Resource Usage]
%% IPFIX
E --> E1[IETF Standard]
E --> E2[Template-Based Export]
E --> E3[Extensible Fields]
E --> E4[Vendor Neutral]
E --> E5[Advanced Analytics]
%% Collection
C4 --> F[Flow Collector]
D4 --> F
E4 --> F
F --> G[Storage Database]
G --> H[Network Monitoring]
G --> I[Anomaly Detection]
G --> J[Malware Detection]
G --> K[Security Analytics]
G --> L[Traffic Engineering]
Flow Toolkit | Network Traffic Flow Toolkit
- Flow Types
- NetFlow
- sFlow
- IPFIX
- Flow Generator and Analyzer
- My Awesome Lists
- Contributing
- Contributors
TCP/IP MODEL
┌─────────────────────────────┐
│ Application │
│ HTTP HTTPS DNS SMTP SSH │◄── IPFIX
├─────────────────────────────┤
│ Transport │
│ TCP UDP SCTP │◄── NetFlow
│ │◄── sFlow
│ │◄── IPFIX
├─────────────────────────────┤
│ Internet │
│ IPv4 IPv6 ICMP │◄── NetFlow
│ │◄── sFlow
│ │◄── IPFIX
├─────────────────────────────┤
│ Network Access │
│ Ethernet VLAN ARP Wi-Fi │◄── sFlow
│ │◄── IPFIX
└─────────────────────────────┘
Technology Application Transport Internet Network Access
NetFlow ✗ ✓ ✓ ✗
sFlow ✗ ✓ ✓ ✓
IPFIX ✓ ✓ ✓ ✓
Who talks to whom? (IP + Ports)
NetFlow
└── Transport + Internet
(TCP/UDP + IP)What is happening on the wire? (Sampled packets + Interfaces)
sFlow
└── Network Access + Internet + Transport
(Ethernet + IP + TCP/UDP)Who talks, how, using what application, and what metadata is available?
IPFIX
└── All TCP/IP Layers
(Application + Transport + Internet + Network Access)flowchart LR
A[TCP/IP Layers]
A --> APP[Application]
A --> TR[Transport]
A --> INET[Internet]
A --> NET[Network Access]
INET --> NF[NetFlow]
TR --> NF
NET --> SF[sFlow]
INET --> SF
TR --> SF
NET --> IPF[IPFIX]
INET --> IPF
TR --> IPF
APP --> IPF
| Tool | Primary role | Input | Output | Best use case | Key advantage | Main consideration |
|---|---|---|---|---|---|---|
| YAF | Flow meter and exporter | Live interface, PCAP | IPFIX, IPFIX-based files | Reference baseline for packet-to-flow conversion | Bidirectional IPFIX flow generation and integration with SiLK | Output may require additional conversion for ML pipelines |
| nProbe | Flow probe, collector and traffic enricher | Live traffic, PCAP, NetFlow, IPFIX, sFlow | NetFlow, IPFIX, JSON | Application-aware monitoring and DPI | Layer 7 application identification through nDPI | Some advanced functionality may require a commercial licence |
| CICFlowMeter | Bidirectional statistical flow generator | PCAP, live interface | CSV | ML/DL intrusion and malware-detection datasets | Produces more than 80 directional and statistical features | Feature definitions, timeouts and duplicated columns require validation |
You can access the my awesome lists here
Contributions of any kind welcome, just follow the guidelines!
