I have found this book interesting and detailed to some extent, I think the idea of using open source tools to do network analysis is good idea, however I got stuck in the perl section where one of the key tools of the book is needed to continue making progress, in this case the author limits to give some tips about how to install or force install on this key "module", however if one fails he remits you to the flow-tool list, which I have found to be slow in terms of response, and finally have left me "stuck" in one of the chapters avoiding me to continue making progress on the book itself.
I know is not the author responsability validate or respond for the tools he recommends, but here this is a show stopper for the book itself, maybe some disk or more friedly help on line tool or KB run by the author followers will help ease this problem (or some basic Unix tips to set up environment variables, etc.... or discuss some common errors...).
I think in general this is a good book to understand flow technology but consider the open tools issues a big warning about having success on using practically this book and be warned that if you want to approach to this book in an useful manner you have to be ready to face some Unix and languages compiling challenges to complete the approach
Kindle电子书价格: | ¥192.93 |

下载免费的 Kindle 阅读软件,即可立即在智能手机、平板电脑或电脑上阅读 Kindle 电子书 - 无需 Kindle 设备。了解更多信息
使用 Kindle 网页版即时在浏览器上阅读。
使用手机摄像头 - 扫描以下代码并下载 Kindle 阅读软件。
![“Network Flow Analysis (English Edition)”,作者:[Michael W. Lucas]](https://images-cn.ssl-images-amazon.cn/images/I/51k-le1UNoL._SX260_.jpg)
Network Flow Analysis (English Edition) 1第一 版本, Kindle电子书
广告
You know that servers have log files and performance measuring tools and that traditional network devices have LEDs that blink when a port does something. You may have tools that tell you how busy an interface is, but mostly a network device is a black box. Network Flow Analysis opens that black box, demonstrating how to use industry-standard software and your existing hardware to assess, analyze, and debug your network.
Unlike packet sniffers that require you to reproduce network problems in order to analyze them, flow analysis lets you turn back time as you analyze your network. You'll learn how to use open source software to build a flow-based network awareness system and how to use network analysis and auditing to address problems and improve network reliability. You'll also learn how to use a flow analysis system; collect flow records; view, filter, and report flows; present flow records graphically; and use flow records to proactively improve your network. Network Flow Analysis will show you how to:
–Identify network, server, router, and firewall problems before they become critical
–Find defective and misconfigured software
–Quickly find virus-spewing machines, even if they’re on a different continent
–Determine whether your problem stems from the network or a server
–Automatically graph the most useful data
And much more. Stop asking your users to reproduce problems. Network Flow Analysis gives you the tools and real-world examples you need to effectively analyze your network flow data. Now you can determine what the network problem is long before your customers report it, and you can make that silly phone stop ringing.
Unlike packet sniffers that require you to reproduce network problems in order to analyze them, flow analysis lets you turn back time as you analyze your network. You'll learn how to use open source software to build a flow-based network awareness system and how to use network analysis and auditing to address problems and improve network reliability. You'll also learn how to use a flow analysis system; collect flow records; view, filter, and report flows; present flow records graphically; and use flow records to proactively improve your network. Network Flow Analysis will show you how to:
–Identify network, server, router, and firewall problems before they become critical
–Find defective and misconfigured software
–Quickly find virus-spewing machines, even if they’re on a different continent
–Determine whether your problem stems from the network or a server
–Automatically graph the most useful data
And much more. Stop asking your users to reproduce problems. Network Flow Analysis gives you the tools and real-world examples you need to effectively analyze your network flow data. Now you can determine what the network problem is long before your customers report it, and you can make that silly phone stop ringing.
- ISBN-13978-1593272036
- 版本1st
- 出版社No Starch Press
- 出版日期2010年6月1日
- 语言英语
- 文件大小1407 KB
Kindle Fire 平板电脑
商品描述
作者简介
Michael W. Lucas is a network/security engineer who keeps getting stuck with network problems nobody else wants to touch. He is the author of the critically acclaimed Absolute FreeBSD, Absolute OpenBSD, Cisco Routers for the Desperate, and PGP & GPG, all from No Starch Press.
Michael W. Lucas is a network/security engineer who keeps getting stuck with network problems nobody else wants to touch. He is the author of the critically acclaimed Absolute FreeBSD, Absolute OpenBSD, Cisco Routers for the Desperate, and PGP & GPG, all from No Starch Press.
--此文字指其他 kindle_edition 版本。目录
; Dedication; ACKNOWLEDGMENTS; INTRODUCTION; Network Administration and Network Management; Network Management Tools; Enough Griping: What's the Solution?; Flow-Tools and Its Prerequisites; Flows and This Book; Chapter 1: FLOW FUNDAMENTALS; 1.1 What Is a Flow?; 1.2 Flow System Architecture; 1.3 The History of Network Flow; 1.4 Flows in the Real World; 1.5 Flow Export and Timeouts; 1.6 Packet-Sampled Flows; Chapter 2: COLLECTORS AND SENSORS; 2.1 Collector Considerations; 2.2 Sensor Considerations; 2.3 Implementing the Collector; 2.4 Installing Flow-tools; 2.5 Running flow-capture; 2.6 How Many Collectors?; 2.7 Collector Log Files; 2.8 Collector Troubleshooting; 2.9 Configuring Hardware Flow Sensors; 2.10 Configuring Software Flow Sensors; 2.11 The Sensor: softflowd; Chapter 3: VIEWING FLOWS; 3.1 Using flow-print; 3.2 Setting flow-print Formats with -f; 3.3 TCP Control Bits and Flow Records; 3.4 ICMP Types and Codes and Flow Records; Chapter 4: FILTERING FLOWS; 4.1 Filter Fundamentals; 4.2 Useful Primitives; 4.3 Filter Match Statements; 4.4 Using Multiple Filters; 4.5 Logical Operators in Filter Definitions; 4.6 Filters and Variables; Chapter 5: REPORTING AND FOLLOW-UP ANALYSIS; 5.1 Default Report; 5.2 Modifying the Default Report; 5.3 Analyzing Individual Flows from Reports; 5.4 Other Report Customizations; 5.5 Useful Report Types; 5.6 Customizing Reports; Chapter 6: PERL, FLOWSCAN, AND CFLOW.PM; 6.1 Installing Cflow.pm; 6.2 flowdumper and Full Flow Information; 6.3 FlowScan and CUFlow; 6.4 FlowScan Prerequisites; 6.5 Installing FlowScan and CUFlow; 6.6 Flow Record Splitting and CUFlow; 6.7 Using Cflow.pm; Chapter 7: FLOWVIEWER; 7.1 FlowTracker and FlowGrapher vs. CUFlow; 7.2 FlowViewer Security; 7.3 Installing FlowViewer; 7.4 Configuring FlowViewer; 7.5 Using FlowViewer; 7.6 FlowGrapher; 7.7 FlowTracker; 7.8 Interface Names and FlowViewer; Chapter 8: AD HOC FLOW VISUALIZATION; 8.1 gnuplot 101; 8.2 Time-Series Example: Bandwidth; 8.3 Automating Graph Production; 8.4 Comparison Graphs; Chapter 9: EDGES AND ANALYSIS; 9.1 NetFlow v9; 9.2 sFlow; 9.3 Problem Solving with Flow Data; 9.4 Afterword; UPDATES; --此文字指其他 kindle_edition 版本。
基本信息
- ASIN : B003VTZXDG
- 出版社 : No Starch Press; 第 1st 版 (2010年6月1日)
- 出版日期 : 2010年6月1日
- 语言 : 英语
- 文件大小 : 1407 KB
- 标准语音朗读 : 已启用
- X-Ray : 未启用
- 生词提示功能 : 未启用
- 纸书页数 : 224页
- 用户评分:
无买家评论
5 星 (0%) |
|
0% |
4 星 (0%) |
|
0% |
3 星 (0%) |
|
0% |
2 星 (0%) |
|
0% |
1 星 (0%) |
|
0% |
评分是如何计算的?
在计算总星级评分以及按星级确定的百分比时,我们不使用简单的平均值。相反,我们的系统会考虑评论的最新程度以及评论者是否在亚马逊上购买了该商品。系统还会分析评论,验证评论的可信度。
此商品在美国亚马逊上最有用的商品评论
美国亚马逊:
4.2 颗星,最多 5 颗星
5 条评论

Amazon Customer
3.0 颗星,最多 5 颗星
Good but in some point the tools are difficult to implement
2012年12月17日 -
已在美国亚马逊上发表已确认购买
2 个人发现此评论有用

Keith Tokash
5.0 颗星,最多 5 颗星
Very practical guide to a confusing topic
2012年8月1日 -
已在美国亚马逊上发表已确认购买
Short version:
Buy this book if you need to deploy Netflow and you're willing to scrap and fight a little to make it happen. Probably saved me a month of dorking around in forums.
Long version.
Netflow and sflow are a bit esoteric for most network admins I know; this book clears up most all the confusion with Netflow, doesn't talk much about sflow. I believe the confusion is a combination of most companies not needing Netflow/sflow, and the tangled wreck the solutions are in. Michael Lucas (ML)'s book untangles a lot of this. Personally when I bought it I was a CCIE with 12 years of experience and I had only a vague notion of how to set up netflow, mostly from the router perspective. Some interesting things ML clears up:
- Netflow isn't Cisco proprietary anymore.
- The industry seems to be moving toward a post-netflow, post-sflow standard. Slowly.
- You can get plenty of actionable information from Netflow without a GUI or any graphs.
- There are about a dozen or more permutations of free software you can use, he recommends the best and guides you to setting them up.
- You have to string multiple programs together, each with its own abilities, syntax and quirks.
Really, if you're going to deploy Netflow on your own, meaning without specialist consultants or a vendor blackbox solution, buy this book. I bought it and had a working Netflow collector within weeks, and like I said above, I didn't know Netflow from Miracle Grow before.
Buy this book if you need to deploy Netflow and you're willing to scrap and fight a little to make it happen. Probably saved me a month of dorking around in forums.
Long version.
Netflow and sflow are a bit esoteric for most network admins I know; this book clears up most all the confusion with Netflow, doesn't talk much about sflow. I believe the confusion is a combination of most companies not needing Netflow/sflow, and the tangled wreck the solutions are in. Michael Lucas (ML)'s book untangles a lot of this. Personally when I bought it I was a CCIE with 12 years of experience and I had only a vague notion of how to set up netflow, mostly from the router perspective. Some interesting things ML clears up:
- Netflow isn't Cisco proprietary anymore.
- The industry seems to be moving toward a post-netflow, post-sflow standard. Slowly.
- You can get plenty of actionable information from Netflow without a GUI or any graphs.
- There are about a dozen or more permutations of free software you can use, he recommends the best and guides you to setting them up.
- You have to string multiple programs together, each with its own abilities, syntax and quirks.
Really, if you're going to deploy Netflow on your own, meaning without specialist consultants or a vendor blackbox solution, buy this book. I bought it and had a working Netflow collector within weeks, and like I said above, I didn't know Netflow from Miracle Grow before.

Jaime Nicolas Diaz
3.0 颗星,最多 5 颗星
Just good.
2013年10月15日 -
已在美国亚马逊上发表已确认购买
The book delivers what it promises. No more, no less.
Having read other books by Michael W. Lucas, I was expecting more contents on working with other netflow systems.
Having read other books by Michael W. Lucas, I was expecting more contents on working with other netflow systems.

Tom Smyth
5.0 颗星,最多 5 颗星
Interesting to the point information on flow analysis
2018年5月14日 -
已在美国亚马逊上发表已确认购买
Interesting read.
Easy to understand.
Concise .
Good information for any network / security engineer / consultant
Examples were clearly explained and concepts were made more accessible to the reader
Easy to understand.
Concise .
Good information for any network / security engineer / consultant
Examples were clearly explained and concepts were made more accessible to the reader