Flow analysis using SiLK
SiLK is a collection of various tools and scripts by CERT NetSA to facilitate analysis in large and vast network setups. SiLK aids the collection, storage, and analysis of the network data, and also enables the security teams to query a variety of historical datasets. Let's perform some analysis over the file from the previous example and make use of different utilities offered by SiLK.
However, before we do that, we need the file under analysis to be in the SiLK format and not the flat IPFIX one. The reason we convert the file into the SiLK format rather than using the flat IPFIX one is that files in the SiLK format are more space-efficient. In the previous example, we converted the PCAP file to the IPFIX format. ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access