<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tanasi.it &#187; software</title>
	<atom:link href="http://www.tanasi.it/tag/software/feed" rel="self" type="application/rss+xml" />
	<link>http://www.tanasi.it</link>
	<description>Alessandro `jekil` Tanasi blog</description>
	<lastBuildDate>Fri, 02 Jul 2010 11:06:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security Testing Tools</title>
		<link>http://www.tanasi.it/1087-security-testing-tools.html</link>
		<comments>http://www.tanasi.it/1087-security-testing-tools.html#comments</comments>
		<pubDate>Sat, 08 Sep 2007 15:59:00 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[security tools]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=1020</guid>
		<description><![CDATA[A list of security testing tools, use it at your own risk.Some of these are old software, but works. You can find it with Google.
Argus     Network transaction monitoring tool (Linux)     broadscan     Broadcast address scannerCerberus Internet Scanner     Windows web server [...]]]></description>
			<content:encoded><![CDATA[<p>A list of security testing tools, use it at your own risk.<br />Some of these are old software, but works. You can find it with <a href="http://www.google.it">Google</a>.</p>
<p>Argus     Network transaction monitoring tool (Linux)     <br />broadscan     Broadcast address scanner<br />Cerberus Internet Scanner     Windows web server vulnerability tester     <br />cgichk     UNIX web server vulnerability tester<br />cgiexp     UNIX web server vulnerability tester     <br />cgiscan     UNIX web server vulnerability tester<br />Cheops     GUI based network mapping tool     <br />Ciscocrack     Password cracker for Cisco<br />Crack     Password cracker for UNIX     <br />Epan     GUI based packet analyzer for Linux<br />Exscan     Network scanner     <br />Fergie     DOS-based packet analyzer<br />firewalk     Determines packet filtering rulesets     <br />fping     UNIX network discovery tool<br />getadmin     Adds user to local Administrators group     <br />gobbler     DOS-based packet analyzer<br />Grinder     Map web servers     <br />hping     Complex scanner with firewalking capability<br />Hunt     Connection monitoring tool     <br />ISS     Network scanner<br />John the Ripper     UNIX password cracker     <br />Juggernaut     TCP hijacking<br />L0phtCrack     NT password cracker     <br />Legion     NetBIOS scanner<br />Linsniff     Sniff Linux passwords     <br />LOKI     Wraps packets in UDP or ICMP headers<br />Mscan     Vulnerability analysis     <br />NAT     NetBIOS Auditing Tool<br />NDSsnoop     Graphically view all object and property details     <br />Nessus     Comprehensive vulnerability analysis tool<br />netcat     TCP/IP multipurpose tool     <br />Nmap     Advanced port scanner, OS detection and analysis tool<br />Nscan     Network scanner     <br />NTFSDOS     Defeat NTFS security from DOS<br />Nwpcrack     NDS password cracker     <br />Ogre     Vulnerability assessment tool<br />NeoTrace     Visual TRACEROUTE     <br />PhoneTag     War dialer<br />Pinger     Ping sweep program     <br />Portscan     Network scanner<br />Pscan     Network scanner     <br />queso     Remote host id<br />Remote password cracking     Remotely crack NT passwords     <br />Revelation     Reveals stored passwords<br />SAINT     Security Administrator&#8217;s Integrated Network Tool     <br />Sam Spade     Whois, nslookup and ping<br />SARA     Security Auditor&#8217;s Research Assistant     <br />SATAN     HTML based vulnerability analysis tool<br />sechole     Adds user to local Administrators group     <br />Sniffit     UNIX packet analyzer<br />SNMPscan     UNIX network discovery tool     <br />Solsniff     Sniffer for Solaris<br />spade     Simple network discovery tool     <br />Strobe     Network scanner<br />tcpdump     Classic packet analyzer     <br />THC-Scan     War-dialer<br />ToneLoc     War-dialer     <br />Twinge     Crashes any Windows box<br />twwwscan     Web sever scanner     <br />Ultrascan     Network scanner<br />VisualRoute     Visual TRACEROUTE     <br />Whisker     UNIX web server vulnerability tester<br />winfingerprint     Fingerprint Windows host     <br />wwwhack     Brute force password attack<br />Xcrush     33 XWindows exploits     <br />xwatchwin     Monitor remote Xwindows sessions</p>
<ul class="related_post"><li><a href="http://www.tanasi.it/952-free-sql-injection-scanners.html" title="Free SQL Injection Scanners">Free SQL Injection Scanners</a></li><li><a href="http://www.tanasi.it/939-netflow-software-list.html" title="Netflow software list">Netflow software list</a></li><li><a href="http://www.tanasi.it/936-voip-security-tool-list.html" title="VoIP Security Tool List">VoIP Security Tool List</a></li><li><a href="http://www.tanasi.it/929-netflow-software.html" title="NetFlow Software">NetFlow Software</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1087-security-testing-tools.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netflow software list</title>
		<link>http://www.tanasi.it/939-netflow-software-list.html</link>
		<comments>http://www.tanasi.it/939-netflow-software-list.html#comments</comments>
		<pubDate>Mon, 21 May 2007 16:42:00 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[netflow]]></category>
		<category><![CDATA[netflow software]]></category>
		<category><![CDATA[network monitoring]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=921</guid>
		<description><![CDATA[Some lists of NetFlow related software.Links:

Free NetFlow Tools
Freshmeat NetFlow

Papers about NetFlow applicationsNetFlow SoftwareStagerDocumentation about NetflowMonitoraggio di rete con NetFlow all&#8217;ESC07]]></description>
			<content:encoded><![CDATA[<p>Some lists of NetFlow related software.<br />Links:
<ul>
<li><a href="http://www.networkuptime.com/tools/netflow/" target="_blank">Free NetFlow Tools</a></li>
<li><a href="http://freshmeat.net/search/?q=netflow&#038;section=projects" target="_blank">Freshmeat NetFlow</a></li>
</ul>
<ul class="related_post"><li><a href="http://www.tanasi.it/1091-papers-about-netflow-applications.html" title="Papers about NetFlow applications">Papers about NetFlow applications</a></li><li><a href="http://www.tanasi.it/929-netflow-software.html" title="NetFlow Software">NetFlow Software</a></li><li><a href="http://www.tanasi.it/184-stager.html" title="Stager">Stager</a></li><li><a href="http://www.tanasi.it/1083-documentation-about-netflow.html" title="Documentation about Netflow">Documentation about Netflow</a></li><li><a href="http://www.tanasi.it/1090-monitoraggio-di-rete-con-netflow-allesc07.html" title="Monitoraggio di rete con NetFlow all&#8217;ESC07">Monitoraggio di rete con NetFlow all&#8217;ESC07</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/939-netflow-software-list.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetFlow Software</title>
		<link>http://www.tanasi.it/929-netflow-software.html</link>
		<comments>http://www.tanasi.it/929-netflow-software.html#comments</comments>
		<pubDate>Thu, 10 May 2007 15:39:05 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[In English]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[flow collection]]></category>
		<category><![CDATA[netflow]]></category>
		<category><![CDATA[netflow software]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=911</guid>
		<description><![CDATA[
 NFDUMP and NfSen

 NFDUMP is a set of tools to capture/record, dump,
filter, and replay NetFlow (v5/v7/9) data.  Can filter flows according
to multiple user-defined profiles. NfSen is a Graphical
Web-based front-end for the NFDUMP tools.  Plots aggregate statistics
over time, supports filtering and drilling down up to the individual
flow level. 
 CoMo 
 Traffic monitoring [...]]]></description>
			<content:encoded><![CDATA[<dl>
<dt> <a name="nfdump"></a><a href="http://nfdump.sourceforge.net/">NFDUMP</a> and <a name="nfsen"></a><a href="http://nfsen.sourceforge.net/">NfSen</a>
</dt>
<dd> <em>NFDUMP</em> is a set of tools to capture/record, dump,<br />
filter, and replay NetFlow (v5/v7/9) data.  Can filter flows according<br />
to multiple user-defined profiles. <em>NfSen</em> is a Graphical<br />
Web-based front-end for the NFDUMP tools.  Plots aggregate statistics<br />
over time, supports filtering and drilling down up to the individual<br />
flow level. </dd>
<dt> <a href="http://como.intel-research.net/">CoMo</a> </dt>
<dd> Traffic monitoring toolkit from Intel Research.  Supports both<br />
continuous real-time processing and retrospective processing.<br />
Supports Netflow and many other traffic capture sources. </dd>
<dt> <a href="http://aircert.sourceforge.net/yaf">YAF</a> &#8211; Yet<br />
Another Flow sensor </dt>
<dd> YAF snoops packets from <tt>pcap</tt> dump files or live capture,<br />
and produces <em>bidirectional</em> flows.  These flows can be sent to<br />
<a href="http://www.switch.ch/tf-tant/floma/references.html#ipfix">IPFIX</a> collectors, or be stored in<br />
an IPFIX-derived file format. </dd>
<dt> <a name="vermont"></a><a href="http://vermont.berlios.de/">VERMONT</a> (VERsatile MONitoring<br />
Toolkit) </dt>
<dd> A reference implementation of the IPFIX and PSAMP protocols<br />
developed as part of the <a href="http://www.history-project.net/">HISTORY</a> project at the<br />
German universities of Erlangen and Tübingen, and of the European<br />
<a href="http://www.diadem-firewall.org/">DIADEM Firewall</a><br />
project. </dd>
<dt> <a href="http://libipfix.sourceforge.net/">libipfix</a> </dt>
<dd> A C library that implements the <a href="http://www.switch.ch/tf-tant/floma/references.html#ipfix">IPFIX protocol</a>. </dd>
<dt> <a name="libfixbuf"></a><a href="http://www.cert.org/netsa/tools/fixbuf/">libfixbuf</a> </dt>
<dd> Aims to be a compliant implementation of the <a href="http://www.switch.ch/tf-tant/floma/references.html#ipfix">IPFIX protocol</a> message format, from<br />
which fully compliant IPFIX Collecting Processes and IPFIX Exporting<br />
Processes may be built.  In addition of the IPFIX Protocol, libfixbuf<br />
supports efficient persistent storage of IPFIX data using the method<br />
outlined in <tt>draft-trammell-ipfix-file-<i>NN</i></tt>. </dd>
<dt> <a href="http://aircert.sourceforge.net/naf">NetSA Aggregated Flow (NAF)<br />
toolchain</a> </dt>
<dd> Tools for creating and analyzing timeslice-organized<br />
bidirectional flow files in the <a href="http://www.switch.ch/tf-tant/floma/references.html#ipfix">IPFIX</a>-inspired <em>NAF</em><br />
format. </dd>
<dt><a name="flowscan"></a><a href="http://net.doit.wisc.edu/%7Eplonka/FlowScan/">FlowScan</a> </dt>
<dd> A Perl-based system to analyze and report on flows collected by<br />
<a href="http://www.switch.ch/tf-tant/floma/software.html#flow-tools"><tt>flow-tools</tt></a>, <tt>lfapd</tt> or <a href="http://www.switch.ch/tf-tant/floma/software.html#cflowd"><tt>cflowd</tt></a>, by <a href="http://net.doit.wisc.edu/%7Eplonka/">Dave Plonka</a>.  <a href="http://wwwstats.net.wisc.edu/">Sample output graphs</a> are<br />
available too, as well as Majordomo-driven <a href="http://net.doit.wisc.edu/%7Eplonka/FlowScan/#Mailing_Lists">mailing<br />
lists</a> for announcements and general discussion (<a href="http://net.doit.wisc.edu/%7Eplonka/list/flowscan/archive/">archive</a>).<br />
It is currently built on <tt><a href="http://net.doit.wisc.edu/%7Eplonka/Cflow/">Cflow.pm</a></tt>.<br />
User-contributed tools based on FlowScan include:</p>
<dl>
<dt> <a href="http://carrierin.sourceforge.net/">CarrierIn</a><br />
    from Stanislav Sinyagin </dt>
<dd> which claims to be more suitable for larger ISP/Carriers
    </dd>
<dt> <a name="cuflow"></a><a href="http://www.columbia.edu/acis/networks/advanced/CUFlow/">CUFlow</a><br />
    from Matt Selsky and Johan M. Andersen at Columbia University </dt>
<dd> which is an alternative graphing tool &quot;designed to combine<br />
    the features of CampusIO and SubNetIO&quot;.  Robert S. Galloway has<br />
    contributed a nice <a href="http://www.dynamicnetworks.us/netflow/">howto-style<br />
    document</a> describing how it can be used. </dd>
<dt> <a href="http://www.columbia.edu/acis/networks/advanced/FlowMonitor/">FlowMonitor</a><br />
    from Johan M. Andersen at Columbia University </dt>
<dd> monitors individual users&#8217; network usage against a bandwidth<br />
    usage policy. </dd>
<dt> <a href="http://users.telenet.be/jurgen.kobierczynski/jkflow/JKFlow.html">JKFlow</a><br />
    by Jurgen Kobierczynski </dt>
<dd> A new reporting module which is highly configurable using an<br />
  XML configuration file. </dd>
<dt> <a name="flowscanplus"></a><a href="http://noc.kreonet2.re.kr/Measurement/">FlowScan+</a> </dt>
<dd> An extension to FlowScan developed by KISTI/KAIST.  Adds<br />
      servlet-based visualization and support for queries for top<br />
      user, AS, port, protocol, etc.  This is supposed to be available<br />
      under <a href="http://flowscan.kreonet2.net/">http://flowscan.kreonet2.net/</a>,<br />
      but that site doesn&#8217;t seem to be responsive. </dd>
</dl>
</dd>
<dt><a name="flow-tools"></a><a href="http://www.splintered.net/sw/flow-tools/"><tt>flow-tools</tt></a> </dt>
<dd> Similar to <a href="http://www.switch.ch/tf-tant/floma/software.html#cflowd"><tt>cflowd</tt></a> but implemented<br />
 as a set of smaller tools, with the addition of compression of the<br />
 recorded data, thus capable of recording many more flows in a given<br />
 amount of disk space.  See <a href="http://www.switch.ch/tf-tant/floma/references.html#osu-id">paper</a><br />
 about its application for Intrusion Detection. There is also a <a href="http://www.pairlist.net/mailman/listinfo/flow-tools">mailing<br />
 list</a> for the package. </p>
<p> There is a short presentation called <a href="http://www.itec.oar.net/oartech/2002-06/oartech06122002.html">Ohio<br />
 Gigapop Traffic Measurements</a> that shows some examples on how<br />
 <tt>flow-tools</tt> can be used. </p>
<p> The package is widely used, and there are quite a few user<br />
 contributions, such as</p>
<dl>
<dt> <a name="FlowViewer"></a><a href="http://ensight.eos.nasa.gov/FlowViewer/"><tt>FlowViewer</tt></a> </dt>
<dd> Web-interface to <a href="http://www.switch.ch/tf-tant/floma/software.html#flow-tools">flow-tools</a>.  Consists<br />
of three tools: <em>FlowViewer</em> provides the user with web access<br />
to many of the textual and statistical flow-tools reports.<br />
<em>FlowGrapher</em> provides a web page with a graph of the selected<br />
flow data. These web pages can be saved.  <em>FlowTracker</em><br />
(introduced in FlowViewer 3.0, released in July 2006) allows the user<br />
to maintain this information long-term by creating four MRTG-like<br />
graphs.  Filtered flow data is collected every five minutes and the<br />
graphs are updated.  FlowTracker requires Tobi Oetiker&#8217;s <a href="http://oss.oetiker.ch/rrdtool/">RRDtool</a> package.<br />
Screenshots are available. </dd>
<dt> <a href="http://security.uchicago.edu/tools/net-forensics"><tt>flow-extract</tt></a>
 </dt>
<dd> which can be used to filter flow-tools-recorded flows through<br />
 user-specified tests </dd>
<dt> a set of <a href="http://cng.ateneo.net/cng/wyu/software/src/"><em>&quot;Inter.netPH<br />
 contribs&quot;</em></a> </dt>
<dd> by Horatio B. Bogbindero </dd>
<dt> some patches and a <a href="http://www.icir.org/robin/flowtools"><em>Python<br />
 module</em></a> </dt>
<dd> by <a href="http://www.icir.org/robin/">Robin Sommer</a>. </dd>
<dt> <a href="http://lusars.net/%7Emhunter/flow-pairs/">flow-pairs</a> </dt>
<dd> A script that extracts lists of the highest bandwidth<br />
    consumers by host and by port.  <a href="http://www.net.berkeley.edu/flow">Installed at<br />
    UCB</a>.  Seems to have similar uses as the older <a href="http://www.switch.ch/tf-tant/floma/software.html#mathe">MATHE</a> system. </dd>
</dl>
</dd>
<dt> <a name="jflow"></a><a href="http://www.net-track.ch/opensource/jflow/">jflow</a> </dt>
<dd> A set of Java classes for collecting and analyzing NetFlow data.<br />
Supports Netflow versions 5 and 6, multithreaded implementation to<br />
facilitate real-time traffic accounting and analysis. </dd>
<dt> <a name="autofocus"></a><a href="http://ial.ucsd.edu/AutoFocus/">Autofocus</a> </dt>
<dd> A traffic analysis and visualization tool that describes the<br />
traffic mix of a link through textual reports and time series plots.<br />
The underlying research is documented in a SIGCOMM 2003 paper,<br />
<em>Automatically Inferring Patterns of Resource Consumption in<br />
Network Traffic</em>, C. Estan, S. Savage, G. Varghese (<a href="http://www.cs.ucsd.edu/users/cestan/papers/p0403-estan.pdf">PDF</a><br />
paper, <a href="http://www.cs.ucsd.edu/users/cestan/papers/TrafficClusters.ppt">PPT</a><br />
slides). </dd>
<dt> <a name="netpy"></a>Wisconsin <a href="http://wail.cs.wisc.edu/netpy/">Netpy</a> </dt>
<dd> Netpy is a network traffic analysis and visualization package<br />
developed at University of Wisconsin-Madison.  This application is<br />
intended for the use of network administrators and it can help<br />
understand usage trends in your network as well as support interactive<br />
analysis of specific network events of interest.  Netpy is distributed<br />
under GPL and a BDS-like license.  Netpy stores NetFlow records in a<br />
local database after applying some sampling to reduce the size of the<br />
data. The analysis engine supports interactive analyses on this data<br />
where the user chooses the time interval of interest, the filtering<br />
rules to apply to the traffic and the type of analysis. The netpy<br />
console allows the user to manage the database, and perform analyses<br />
interactively or through scripts. The graphical user interface<br />
visualizes the results of the analyses accessing the database locally<br />
or remotely through a netpy server that is also part of the<br />
package. </dd>
<dt> <a href="http://stager.uninett.no/">Stager</a><a name="stager"></a> </dt>
<dd> Stager is a system for aggregation and presentation of network<br />
statistics from the flow-tools package.  Includes PostgreSQL storage<br />
of aggregated statistics, as well as a Web frontend.  A public <a href="http://stager.uninett.no/">demo</a> is available. </dd>
<dt><a name="nfstat"></a><a href="http://www.internet2.edu/%7Eshalunov/nfstat/">nfstat</a> </dt>
<dd> Developed to analyze (sampled) Netflow data from the Internet2<br />
<em>Abilene</em> backbone.  This is used to generate the <a href="http://netflow.internet2.edu/weekly/">Internet2 NetFlow Weekly<br />
Reports</a>, which contain interesting statistics not easily found<br />
elsewhere, such as distribution of bulk flow throughput.  There are<br />
two mailing lists for <a href="https://mail.internet2.edu/wws/info/nfstat-announce">announcements</a><br />
and for <a href="https://mail.internet2.edu/wws/info/nfstat-users">user<br />
discussions</a>, respectively. </dd>
<dt><a name="cflowd"></a><a href="http://www.caida.org/tools/measurement/cflowd/">CAIDA cflowd</a></dt>
<dd> Rather complex system with distributed log servers.  Released in<br />
 1998, this was the first open-source software system to work on<br />
 NetFlow data, but doesn&#8217;t seem to be maintained anymore.  CAIDA have<br />
 prepared a nice <a href="http://www.caida.org/tools/measurement/cflowd/newfaq.xml">FAQ</a><br />
 which contains interesting information both on Cflowd and on NetFlow<br />
 in general.  CAIDA has announced that they no longer support cflowd,<br />
 and recommend that people move to <a href="http://www.switch.ch/tf-tant/floma/software.html#flow-tools"><tt>flow-tools</tt></a> instead. </dd>
<dt><a name="aflow"></a><a href="http://www.aflow.org/">Aflow</a> </dt>
<dd>Small Netflow monitoring tool developed by ARIN, available under<br />
GPL.  Features include easy configuration, maintenance of and graph<br />
generation from <a href="http://www.rrdtool.org/">RRDtool</a> files,<br />
pf/tcpdump-style filter rules.  There is a mailing list for<br />
announcements and discussion. </dd>
<dt><a name="asflow"></a><a href="http://asflow.sourceforge.net/">ASFLOW</a> (already missing in<br />
action?) </dt>
<dd> Tool to analyze traffic to &quot;would-be&quot; BGP neighbors.  <a href="http://www.nanog.org/mtg-0510/steenbergen.html">Presented</a> by<br />
Richard Steenbergen and Nathan Patrick at <a href="http://www.nanog.org/mtg-0510/agenda.html">NANOG 35</a>, October<br />
2005.  There is supposed to be both an easy-to-use Perl version and a<br />
high-performance (but somewhat complex) C version. </dd>
<dt><a name="fluxoscope"></a><a href="http://www.switch.ch/network/stat/fluxoscope/">Fluxoscope</a></dt>
<dd> Software used for charging, monitoring, and traffic analysis at<br />
SWITCH.  Includes its own NetFlow v5 accounting receiver which<br />
aggregates traffic into multidimensional matrices<br />
(AS/site/application).  Most of the software is written in Common<br />
Lisp. </dd>
<dt> <a name="samplicator"></a><a href="http://www.switch.ch/tf-tant/floma/sw/samplicator/">UDP<br />
Samplicator</a> </dt>
<dd> A small program that receives UDP datagrams and redistributes<br />
them to a set of receivers.  Useful to distribute NetFlow accounting<br />
streams to multiple post-processing programs.  Is able to distribute<br />
only a specified percentage of all packets to each receiver.  Note<br />
that recent versions added the possibility of &#8220;spoofing&#8221; the<br />
original sender&#8217;s IP address. </dd>
<dt> <a name="anontool"></a><a href="http://www.ics.forth.gr/dcs/Activities/Projects/anontool.html">Anonymization<br />
Application Programming Interface (AAPI)/AnonTool</a> </dt>
<dd> An open-source implementation of Anonymization API.  Includes a<br />
set of ready-to-use applications for anonymization of Netflow (v5 and<br />
v9), as well as PCAP traces. </dd>
<dt> <a name="canine"></a><a href="http://security.ncsa.uiuc.edu/distribution/CanineDownLoad.html">CANINE</a>
</dt>
<dd> &quot;A NetFlows Conversion/Anonymization Tool for Format<br />
Interoperability and Secure Sharing&quot;.  Converts NetFlow data between<br />
various formats including NetFlow v5 and v7, <a href="http://www.switch.ch/tf-tant/floma/software.html#nfdump">NFDUMP</a>, CiscoNCSA and ArgusNCSA, and is able to<br />
apply various methods of anonymization based on user configuration.<br />
See also the <a href="http://www.switch.ch/tf-tant/floma/A%20NetFlows%20Conversion/Anonymization%20Tool%20forFormat%20Interoperability%20and%20Secure%20Sharing">FlowCon 2005 paper</a> by<br />
K. Luo, Y. Li, A. Slagell, and W. Yurick. </dd>
<dt> <a name="panoptis"></a><a href="http://panoptis.sourceforge.net/">Panoptis</a> </dt>
<dd> An open-source project started in 2001 by Costas Kotsokalis of<br />
GRNET.  Uses NetFlow accounting data to detect (Distributed) Denial of<br />
Service attacks.  Status as of November 2006: Supports NetFlow v1, v5<br />
and v8 (router-aggregated) (with v8 untested for its biggest<br />
part). The system supports proof-of-concept attack trace-back using a<br />
mesh of detectors.  Updates have been introduced so that the project<br />
compiles on newer systems. </dd>
<dt> <a name="flamingo"></a><a href="http://flamingo.merit.edu/">Flamingo</a> </dt>
<dd> Real-time 3D traffic visualization system developed at <a href="http://www.merit.edu/">Merit</a>.  This client/server system<br />
based on Netflow and OpenGL plots traffic patterns by IP address, AS,<br />
or port numbers, and allows interactive exploration of this data.<br />
Sample graphics and a paper are available from the Website. </dd>
<dt> <a href="http://mhtg.the.net/mhtg.html">MHTG</a><br />
(Multi Host Traffic Grapher)</dt>
<dd> Uses NetFlow to generate per-host graphs of traffic for a campus<br />
network.  Nice user interface implemented as a Java applet which<br />
allows interaction with traffic plots.  The software consists of a C++<br />
program to process NetFlow data, a Mysql backend, and Perl frontend<br />
and the Java grapher. </dd>
<dt> <a href="http://buckaroo.xo.com/CFLOWD/">Matt&#8217;s Quick &amp; Dirty CFLOWD tutorial and scripts&#8230;</a></dt>
<dd> Postprocessing scripts for <tt>cflowd</tt> data by Matthew Petach</dd>
<dt> <a href="http://formenos.org/flow/"><tt>flow2rrd.pl</tt></a> </dt>
<dd> <cite>Converts a cisco NetFlow stream into set of RRDtool files, based<br />
        on set of IP netmasks.</cite>  By Alex Pilosov. </dd>
<dt> <a name="bmpcount"></a><a href="http://ial.ucsd.edu/bitmaps/">bmpcount</a> </dt>
<dd> A library of bitmap counting algorithms that count the number of<br />
active flows in a network traffic trace. To be able to use it, you<br />
should be familiar with the paper that describes the algorithms it<br />
implements: _Bitmap algorithms for counting active flows on high speed<br />
links_, C. Estan, G. Varghese, M. Fisk, Internet Measurement<br />
Conference 2003 (<a href="http://www.cs.ucsd.edu/users/cestan/papers/p327-estan-bitmaps.pdf">PDF</a><br />
paper, <a href="http://www.cs.ucsd.edu/users/cestan/papers/FlowCountingBitmaps.ppt">PPT</a><br />
slides) </dd>
<dt> Slate </dt>
<dd> An application that converts LFAP data into NetFlow records &#8211; see<br />
<a href="http://www.nmops.org/">http://www.nmops.org/</a>. </dd>
<dt> <a href="http://www.ntop.org/netflow.html">Ntop</a> </dt>
<dd> This well-known libpcap-based network usage monitor has been<br />
extended to produce NetFlow v5 accounting data.  It also supports<br />
<a href="http://www.switch.ch/tf-tant/floma/references.html#sflow">sFlow</a>. </dd>
<dt> <a name="silk"></a><a href="http://silktools.sourceforge.net/">SiLK</a> </dt>
<dd> SiLK, the System for Internet-Level Knowledge, is a collection of<br />
netflow tools developed by the <a href="http://www.cert.org/">CERT</a>/NetSA (Network Situational<br />
Awareness) Team to facilitate security analysis in large networks.<br />
The toolset includes programs such as <tt>rwfilter</tt>,<br />
<tt>rwcount</tt>, <tt>rwuniq</tt>.  There are plans to develop this<br />
further into an &quot;Analyst&#8217;s Desktop&quot;, described in a FloCon&#8217;05 paper,<br />
<i>R: A Proposed Analysis and Visualization Environment for Network<br />
Security Data</i>, J. McNutt (<a href="http://www.cert.org/flocon/2005/presentations/flocon2005-rintro2.pdf">PDF</a>).<br />
<i>(Ed.: Should this be &quot;RAVE: A Proposed&#8230;&quot;?)</i><br />
The idea is to base this on the <em>R</em> statistical programming<br />
language (see <a href="http://www.r-project.org/">www.r-project.org</a>), which<br />
supports exploratory data analysis well. </dd>
<dt> <a name="jnca"></a><a href="http://sourceforge.net/projects/jnca">Java Netflow<br />
Collect-Analyzer</a> </dt>
<dd> Collects Netflow v1/v5/v7/v8/v9 packets from Cisco/Juniper<br />
routers or nProbe.  It can store both raw data or analyzed contents to<br />
a database using JDBC. </dd>
<dt> <a name="upframe"></a><a href="http://www.tik.ee.ethz.ch/%7Eddosvax/upframe/">UPFrame</a>
</dt>
<dd> This <em>UDP/Netflow Processing Framework</em> is a system for<br />
real-time processing of UDP packet streams such as Netflow export<br />
data.  It features a general infrastructure for dynamically<br />
configurable plugin modules. </dd>
<dt> <a name="nprobe"></a><a href="http://www.ntop.org/nProbe.html">nProbe</a> </dt>
<dd> A small self-contained program that generates NetFlow accounting<br />
data for a traffic stream sniffed off one or several interfaces.<br />
Works under Unix and Windows environments.  It can be used to build<br />
inexpensive NetFlow probes. </dd>
<dt> <a name="fprobe"></a><a href="http://sourceforge.net/projects/fprobe/">fprobe</a> (I) </dt>
<dd> Traffic probe that can generate NetFlow data.  Based on the<br />
libpcap library.  Fairly small implementation in C. </dd>
<dt> <a name="fprobe-ro"></a><a href="http://psi.home.ro/flow">fprobe</a> (II)
</dt>
<dd> Another NetFlow-generating software traffic probe. </dd>
<dt> <a name="softflowd"></a><a href="http://www.mindrot.org/softflowd.html">Softflowd</a> </dt>
<dd> Traffic probe that can generate NetFlow data.  Based on libpcap.<br />
Comes with a NetFlow collector in Perl.  Both the server (probe) and<br />
client (collector) support export/import over IPv6.  Very lean (as of<br />
June 2004) implementation in C. </p>
<p><a name="pfflowd"></a>The <a href="http://www.mindrot.org/pfflowd.html"><tt>pfflowd</tt></a><br />
variant is based on OpenBSD&#8217;s PF interface. </p>
<p><a name="flowd"></a>The <a href="http://www.mindrot.org/flowd.html"><tt>flowd</tt></a> companion<br />
NetFlow collector includes features such as multicast, IPv6 and<br />
NetFlow v9 support, as well as fast upfront filtering. </dd>
<dt> <a href="http://www.qosient.com/argus/">Argus</a> from QoSient
</dt>
<dd> This network <em>Audit Record Generation and Utilization<br />
 System</em> can be used for intrusion detection and QoS<br />
 monitoring.  It is also <a href="http://www.switch.ch/tf-tant/floma/references.html#argus">mentioned</a><br />
 in the reference section of these pages. </dd>
<dt> <a href="http://pasillo.renater.fr/renetcol/">RENETCOL</a><br />
(RENATER Network Collector) </dt>
<dd> GPL&#8217;ed Netflow collector with support for Netflow v9, IPv6,<br />
Multicast, and MPLS. </dd>
<dt> <a href="http://netacad.kiev.ua/flowc/">Flowc</a> </dt>
<dd> &quot;a tool for gathering, storing and analyzing traffic accounting<br />
for Cisco routers with NetFlow enabled switching (version 5).  This<br />
package could be used by ISP for planning, analysis and billing<br />
procedures.&quot; </dd>
<dt>CESNET <a name="cesnet"></a><a href="http://netflow.cesnet.cz/">NetFlow Monitor</a></dt>
<dd>by Jan Nejman. </dd>
<dt> <a name="rus"></a> <a href="http://cert.uni-stuttgart.de/projects/flows/">RUS-CERT tools</a>
</dt>
<dd> The CERT of the Stuttgart University computing center (RUS-CERT)<br />
has published some tools that they use internally to analyze Netflow<br />
data.  Some of the documentation is in German. </dd>
<dt> <a name="pmacct"></a><a href="http://www.pmacct.net/">pmacct</a>
</dt>
<dd> A set of tools to account and aggregate IP traffic.  Supports<br />
<tt>libpcap</tt>, Netflow v1/v5/v7/v8/v9, and sFlow v2/v4/v5 for both<br />
IPv4 and IPv6 traffic. </dd>
<dt> <a href="http://freshmeat.net/projects/neye">NEye</a> </dt>
<dd> NEye is a Netflow V5 collector.  It logs incoming Netflow V5 data<br />
to ASCII, MySQL, or SQLite databases, and it makes full use of POSIX<br />
threads if available.  It works on most major platforms (Linux,<br />
Solaris, AIX, Irix, HP/UX, Mac OS X, Digital Unix, etc.) and older<br />
ones too (Ultrix, Nextstep, etc.). </dd>
<dt><a name="netflow2mysql"></a><a href="http://cluster19.aist-nara.ac.jp/public/#NetFlow2MySQL">NetFlow2MySQL</a>,<br />
<a href="http://cluster19.aist-nara.ac.jp/public/#NetFlow2XML">NetFlow2XML</a>,<br />
and <a href="http://cluster19.aist-nara.ac.jp/public/#pcNetFlow">pcNetFlow</a>
</dt>
<dd>Three products from a research project at the NARA Institute of<br />
Science and Technology. </dd>
<dt><a name="flavio"></a><a href="http://flavio.sourceforge.net/">F.L.A.V.I.O.</a> (see also the <a href="http://freshmeat.net/projects/flavio/">FreshMeat</a> page)</dt>
<dd> A Perl-based NetFlow collector that stores flow data &quot;into a<br />
MySQL database and gets it back to graph daily, weekly, monthly and<br />
yearly charts.&quot; </dd>
<dt> <a href="http://www.auckland.ac.nz/net/NeTraMet/">NetFlowMet</a> </dt>
<dd> Starting with release 4.2, Nevil Brownlee&#8217;s <em>NeTraMet</em><br />
package includes <em>NetFlowMet</em>, which implements an RTFM meter<br />
fed on Netflow accounting data. </dd>
<dt> <a href="http://www.ibh.de/%7Ebeck/stuff/nfa/">NetFlow Accounting<br />
software</a> from <a href="http://www.switch.ch/cgi-bin/info/whois?Query=ABP-RIPE&#038;Server=whois.ripe.net">ABPSoft</a></dt>
<dd> A self-contained NetFlow processing system written in C.  Writes<br />
captured flows to file.  Postprocessor breaks up this data over peers<br />
according to a definition file. </dd>
<dt> <a href="http://ehnt.sourceforge.net/">EHNT</a><br />
(Extreme Happy NetFlow Tool) by Nik Weidenbacher </dt>
<dd> Another self-contained NetFlow accounting packet processor.  The<br />
receiving process also functions as a server to which various kinds of<br />
clients can connect.  Also written in C. </dd>
<dt> <a href="ftp://hvs.envisage.co.za/pub/cflowd-hvt">Hendrik<br />
Visage&#8217;s NetFlow tools</a> </dt>
<dd> FTP site with various tools for NetFlow postprocessing.  In<br />
particular, you will find:</p>
<ol>
<li> a UDP duplicator (hack of samplicator to preserve the source router<br />
IP) </li>
<li> a couple of hacks to cflowd for dumping the flows every %n<br />
seconds as well as a &quot;<tt>flhh</tt>&quot; to output flowdump stuff<br />
aggregated, ready for a<br />
<tt>`grep|sed &quot;s/../update  /&quot;|rrdtool -`</tt> </li>
</ol>
</dd>
<dt> <a href="http://www.switch.ch/tf-tant/floma/www.netmet-solutions.org">netMET</a> &#8211; Network&#8217;s<br />
METrology </dt>
<dd> Network measurement solution for the French regional academic<br />
networking community, developed at the C.I.R.I.L in Nancy.  Includes<br />
an HTML interface and support for accounting and security<br />
monitoring. </dd>
<dt> <a name="mathe"></a><a href="http://sawww.epfl.ch/SIC/SA/publications/FI98/fi-4-98/4-98-page5.html">MATHE</a></dt>
<dd> An article (in French) about a Netflow accounting and<br />
visualization system used at <a href="http://www.epfl.ch/">EPFL</a>.<br />
Uses an Oracle database and Perl DBI/GD scripts to generate a nice<br />
breakdown of external traffic to departments/institutes. </dd>
<dt> <a href="http://bill.ja.net/">JANET Traffic Accounting Site</a> </dt>
<dd> An impressive application of Netflow which is used for<br />
volume-based charging for JANET&#8217;s U.S. connection.<br />
 <a href="http://statto.ukerna.ac.uk/">Other statistics</a> at JANET<br />
 were done using NeTraMet. </dd>
<dt> InMon <a href="http://www.inmon.com/sflowTools.htm">sFlow Toolkit</a>
</dt>
<dd> Open source tools for analyzing sFlow data. Allows sFlow data to<br />
be used with a number of open source tools, including: tcpdump, snort<br />
and MRTG or rrdtool.  Also able to convert sFlow packets to NetFlow<br />
packets. </dd>
<dt> <a name="net-sflow"></a><a href="http://search.cpan.org/search?query=Net%3A%3AsFlow&#038;mode=all">Net::sFlow</a> </dt>
<dd> Perl module to parse sFlow messages.  Written by Elisa Jasinska<br />
from AMS-IX as a basis of the sFlow-based traffic analysis service for<br />
AMS-IX members.  The use of this at AMS-IX has been described in<br />
presentations and a paper, links to which can be found in<br />
  the <a href="http://www.switch.ch/tf-tant/floma/references.html#sflow-amsix">references section</a>. </dd>
</dl>
<h3> <a name="netflow-commercial">Commercial Applications</a> </h3>
<dl>
<dt> <a name="apg"></a><a href="http://www.watch4net.com/apg/">Watch4net APG (Automated<br />
Performance Grapher)</a> </dt>
<dd> APG is a reporting tool that provides performance and capacity<br />
reports on network, servers, applications and Netflow data. </dd>
<dt> <a href="http://www.apogeenet.com/">Apogee Networks</a> </dt>
<dd> The <em>NetCountant</em> network usage-based billing system and<br />
the <em>NetScope</em> real-time network monitoring and performance<br />
analysis solution support NetFlow, RMON2, RADIUS, other SNMP MIBs, and<br />
&#8220;Layer 7&#8221; application/content switches. </dd>
<dt> <a href="http://www.arbornetworks.com/">Arbor Networks</a> </dt>
<dd> <em>Peakflow DOS</em> detects denial-of-service attacks, and<br />
<em>Peakflow Traffic</em> analyzes traffic and routing history.  Both<br />
can process NetFlow accounting data.  As of November 2003, Arbor is<br />
said to support Netflow v9. </dd>
<dt> <a name="bento"></a><a href="http://www.networksignature.com/">Network Signature</a> BENTO </dt>
<dd> BENTO stands for &#8220;BGP Enabled Network Traffic Organizer&#8221; and is<br />
a high-performance NetFlow data processor with an integrated BGP-4<br />
implementation to facilitate traffic analysis based on complex<br />
external routing relationships.  Product offerings include a<br />
software/support package and an &#8220;appliance&#8221; consisting of a<br />
preconfigured rack-mount server. </dd>
<dt> <a name="cfi"></a><a href="http://www.caligare.com/">Caligare Flow Inspector</a><br />
and <a name="netimonitor"></a><a href="http://www.netimonitor.com/">NetImonitor</a> </dt>
<dd> Analyzes NetFlow data for network monitoring as well as attack<br />
detection and response.  Works with NetFlow data export version<br />
1,5,6,7 and 9.  NetImonitor is primarily designed for use in the<br />
United States. </dd>
<dt> <a href="http://www.cisco.com/">Cisco</a> </dt>
<dd> <a href="http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/nfc/index.htm"><em>NetFlow<br />
FlowCollector</em></a>/<a href="http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/nda/index.htm"><em>Network<br />
Data Analyzer</em></a> </p>
<p>Similar to <tt>cflowd</tt> but productized, with a (Java-based)<br />
GUI and possibly better possibilities of defining filters and<br />
aggregation schemes.</p>
<ul>
<li> NetFlow Collector 3.6 <a href="http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/nfc/nfc_3_6/index.htm">documentation</a>,<br />
demo version <a href="http://www.cisco.com/pcgi-bin/tablebuild.pl/collector">download</a>
</li>
<li> Network Data Analyzer 3.6 <a href="http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/nda/index.htm">documentation</a>,<br />
demo version (3.0) <a href="http://www.cisco.com/pcgi-bin/tablebuild.pl/analyzer"><br />
download</a> </li>
</ul>
</dd>
<dt> Cisco <a href="http://www.cisco.com/warp/public/cc/pd/ifaa/6000nam/index.shtml">NAM<br />
(Network Analyzer Module)</a> </dt>
<dd> This is a &quot;NetFlow collector on a linecard&quot; for the Catalyst<br />
6500/7600 OSR platform. </dd>
<dt> <a href="http://www.concord.com/">Concord</a> </dt>
<dd> <em>Network Health</em> uses NetFlow and RMON2 accounting<br />
information &#8220;to determine application, bandwitdth and server usage.&#8221;
</dd>
<dt> Crannog Software&#8217;s <a href="http://www.crannog-software.com/netflow.html">Netflow<br />
Monitor</a> </dt>
<dd> LAN and WAN bandwidth analysis based on NetFlow data.  Includes a<br />
Web interface including Java applets to display traffic graphs and to<br />
enable drill-down.  Runs on Microsoft Windows NT4/2000/XP and on Unix.<br />
Evaluation version of <em>NetFlow Live</em> <a href="http://www.crannog-software.com/download.html">available</a>. </dd>
<dt> <a href="http://www.cyclades.com/products/29/nquirer">Cyclades-nQuirer</a> </dt>
<dd> A network traffic monitoring appliance that can generate data in<br />
both Netflow and nTop formats. </dd>
<dt> <a href="http://www.digiquant.com/">Digiquant</a> </dt>
<dd> <em>IMS</em> accounting and billing system based on<br />
Oracle 9i under Unix. </dd>
<dt> <a href="http://www.gadgets.co.nz/">Gadgets Software &amp;<br />
Professional Services Ltd.</a></dt>
<dd> <a href="http://www.gadgets.co.nz/products.shtml"><em>Network<br />
Intelligence</em></a> traffic measurement and visualisation software<br />
for GNU/Linux and Windows (client only) platforms.  Free trial<br />
available.  Includes 3D visualization using OpenGL. </p>
<p>The author also wrote <tt><a href="http://www.gadgets.co.nz/ni_dl/bbnfc.shtml">bbnfc</a></tt>, a<br />
&#8220;bare-bones Netflow collector tool&#8221; that simply receives and<br />
displayes Netflow v5 packets. </dd>
<dt> <a href="http://www.hp.com/">Hewlett-Packard</a> </dt>
<dd> The <em>Smart Internet Billing Solution</em> usage management<br />
system and well as <em>OpenView Performance Insight for Networks</em><br />
(OVPI) use NetFlow accounting data as possible input. </dd>
<dt> <a name="stablenet"></a><a href="http://www.infosim.net/">Infosim<br />
StableNet</a> &#8211; Performance Management Engine </dt>
<dd> StableNet PME provides End-to-End (E2E) Service Level Management<br />
(SLM) by monitoring and reporting on the systems, networks and<br />
applications.  StableNet supports the following flow technologies out<br />
of the box: Netflow, cFlow, sFlow, Netstream. </dd>
<dt> <a href="http://www.infovista.com/">InfoVista Corporation</a></dt>
<dd> <em>InfoVista</em> Service Level Management (SLM) and conformance<br />
solution. </dd>
<dt> <a href="http://www.inmon.com/products/trafficsentinel.php">InMon Traffic<br />
Sentinel</a> </dt>
<dd> is a commercial, web-based application running on Linux that<br />
provides real-time and historical analysis of flow information from<br />
NetFlow, sFlow, LFAP or HP Extended RMON sources.  Web queries provide<br />
easy access to historical traffic matrices. Real-time top talker<br />
charts identify sources of congestion.  Includes network-wide<br />
threshold and alert features as well as anomaly detection. </dd>
<dt> <a href="http://www.isarflow.de/">IsarFlow</a> from IsarNet </dt>
<dd> IsarFlow is a traffic analysis tool for accounting, capacity<br />
planning, QoS monitoring, and application distribution within Citrix<br />
sessions based on Netflow. </dd>
<dt> <a href="http://www.ixiacom.com/">Ixia</a></dt>
<dd> <em>IxTraffic</em> integrates NetFlow accounting data with<br />
topology information from a live BGP-4 feed to allow analysis of<br />
inter-domain traffic patterns. </dd>
<dt> <a name="lancope"></a><a href="http://www.lancope.com/">Lancope</a> StealthWatch </dt>
<dd> Flow-based Network Behavior Analysis appliance with advanced user<br />
identity tracking.  Can handle Netflow and sFlow data, or capture<br />
packets from mirrored ports. </dd>
<dt> <a name="loriotpro"></a><a href="http://www.loriotpro.com/">LoriotPro</a> </dt>
<dd> A network monitoring (&quot;supervision&quot; in franglais) system that<br />
includes a <a href="http://www.loriotpro.com/Products/Plugins/Plugins_EN.htm#Netflow">Netflow<br />
plugin</a>.  Stores flow data in a MySQL database. </dd>
<dt> <a name="manageengine"></a><a href="http://manageengine.adventnet.com/products/netflow/">ManageEngine<br />
NetFlow Analyzer</a> </dt>
<dd> Netflow-based bandwidth monitoring tool from AdventNet.  Supports<br />
location of bottlenecks and allows drilling down to find traffic that<br />
is causing them.  Thirty-day evaluation license available free of<br />
charge.  Versions for Windows and Linux (x86). </dd>
<dt> <a name="mazu"></a><a href="http://www.mazunetworks.com/">Mazu Networks</a> </dt>
<dd> <a href="http://www.mazunetworks.com/products/mazu-profiler.php">Mazu<br />
Profiler</a> analyzes and models enterprise network traffic.  It<br />
provides visibility into network behavior, protects against worms and<br />
other malware, and supports auditing and policy enforcement.  It<br />
supports Netflow v1/5/7/9 as well as other data collection mechanisms.
</dd>
<dt> <a href="http://www.micromuse.com/">Micromuse</a> </dt>
<dd> <em>Cisco Info Center USM</em> &#8220;acquires, analyzes, displays and<br />
exports Internet usage data.&#8221;  Note that Micromuse was integrated<br />
into IBM under the &quot;IBM Tivoli Netcool&quot; brand. </dd>
<dt><a href="http://www.narus.com/">NARUS</a></dt>
<dd> <em>OSS Mediation solutions.</em> They also do anomaly<br />
detection. </dd>
<dt> <a href="http://www.nazca-billing.com/index.htm">Nazca.Billing</a> </dt>
<dd> Integrated billing software for &quot;Telephony, Internet and<br />
Networks&quot;.  Contains interfaces to many accounting systems including<br />
NetFlow. </dd>
<dt> <a name="netqos"></a><a href="http://www.netqos.com/solutions/reporteranalyzer/index.html">NetQoS<br />
ReporterAnalyzer</a> </dt>
<dd> Scalable solution for network capacity planning, troubleshooting,<br />
and traffic analysis, including traffic visualization capabilities.
</dd>
<dt> <a name="netup"></a><a href="http://netup.biz/">NetUp</a><br />
Products </dt>
<dd> <a href="http://www.netup.biz/utm5.php">UTM</a> is a billing<br />
system for ISPs.  It can use Netflow (v5) and several other accounting<br />
methods.  It supports a rich variety of charging and payment<br />
schemes. </p>
<p><a href="http://www.netup.biz/ndsad.php">NDSAD Traffic<br />
Collector</a> is an open-source (GPL&#8217;ed) tool that captures packets<br />
and generates a Netflow (v5) accounting stream. </dd>
<dt> <a name="netusage"></a><a href="http://www.netusage.net/">NetUsage</a> from Apoapsis (formerly<br />
called WANBUS) </dt>
<dd> The NetUsage suite strives to provide visibility of network<br />
traffic, producing meaningful reports not only for network<br />
professionals, but for IT management, business managers and accounts<br />
departments.  Supports network traffic monitoring, capacity planning,<br />
business justification and cost control. </dd>
<dt> SolarWinds <a name="orion"></a><a href="http://www.solarwinds.net/products/orion/netflowtrafficanalyzer.aspx">Orion NetFlow Traffic Analyzer</a>   </dt>
<dd> Windows-based commercial system that stores NetFlow data,<br />
  generates various types of charts, and provides &quot;drill-down&quot;<br />
  capabilities. </dd>
<dt> <a name="paessler"></a><a name="prtg"></a><a href="http://www.paessler.com/prtg/">PRTG Traffic Manager</a> </dt>
<dd> Windows-based bandwidth management software from <a href="http://www.paessler.com/">Paessler</a>.  Uses SNMP, Netflow, and<br />
packet capture for monitoring and classifying bandwidth usage.<br />
Besides the commercial license, there is also a (restricted)<br />
&quot;freeware&quot; license. </dd>
<dt> QRadar from <a href="http://www.q1labs.com/">Q1 Labs</a>
</dt>
<dd> The system can use Netflow data, but also includes its own<br />
payload-aware flow collector which produces bi-directional flow<br />
information in a format called QFlow.  Includes anomaly<br />
detection. </dd>
<dt> <a name="scrutinizer"></a>Plixer <a href="http://www.plixer.com/products/scrutinizer.php">Scrutinizer NetFlow Analyzer</a> </dt>
<dd> NetFlow-based Enterprise-level traffic analysis tool with<br />
GUI-based reporting (topN hosts/applications etc.) and<br />
zoom/drill-down.  Uses MySQL<br />
back-end.  <a href="http://www.plixer.com/products/free-netflow.php">Free (as in<br />
free beer) edition</a> available. </dd>
<dt> <a href="http://www.tekyazilim.com/i-aba-en.htm">I-ABA</a> and <a href="http://www.tekyazilim.com/mntm-tr.htm">M-NTM</a> from <a href="http://www.tekyazilim.com/">Tek Yazilim</a></dt>
<dd> Windows-based software to analyze NetFlow (and Cisco IP<br />
Accounting) statistics.  I-ABA specifically analyzes AS-to-AS traffic<br />
streams.  Trial versions can be downloaded. </dd>
<dt> <a name="quallaby"></a><a href="http://www.quallaby.com/">Quallaby</a> </dt>
<dd> Has a Netflow Application Pack for its <em>PROVISO</em> system<br />
for network performance monitoring and service assurance.  Quallaby<br />
was acquired by Micromuse, which was itself acquired by IBM.  The<br />
Netflow Application Pack is maintained in the 4.4.1 release and<br />
supports Netflow versions up to v8. </dd>
<dt> <a href="http://www.netscout.com/">NetScout</a></dt>
<dd> <em>nGenius Performance Manager</em> &#8220;is a complete solution for<br />
proactive monitoring, troubleshooting, capacity planning, and Voice<br />
over IP (VoIP) monitoring&#8221;. </dd>
<dt> <a href="http://www.portal.com/">Portal Software</a> </dt>
<dd> <em>Infranet</em> real-time customer management and billing<br />
software. </dd>
<dt> <a href="http://www.rodopi.com/">RODOPI</a> </dt>
<dd> Billing software for ISPs. </dd>
<dt> <a href="http://www.xacct.com/">XACCT</a></dt>
<dd> Commercial vendor of accounting and billing solutions with the<br />
ability to process (among others) Netflow accounting data</dd>
</dl>
<ul class="related_post"><li><a href="http://www.tanasi.it/939-netflow-software-list.html" title="Netflow software list">Netflow software list</a></li><li><a href="http://www.tanasi.it/1091-papers-about-netflow-applications.html" title="Papers about NetFlow applications">Papers about NetFlow applications</a></li><li><a href="http://www.tanasi.it/184-stager.html" title="Stager">Stager</a></li><li><a href="http://www.tanasi.it/158-netflow-analysis-tool-flowscan.html" title="NetFlow analysis tool: FlowScan">NetFlow analysis tool: FlowScan</a></li><li><a href="http://www.tanasi.it/1114-appunti-su-netflow.html" title="Appunti su NetFlow">Appunti su NetFlow</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/929-netflow-software.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
