Towards ntopng v4: New User Interface Featuring Dark Theme

Posted · Add Comment

This February we’ll introduce ntopng v4 and we’re starting to write some blog posts to preview the new features. Let’s start with the user interface. Since v1 the UI has always been the same. People however asked us some more flexible layout where it is possible for instance to switch across network interfaces in a […]

Introducing Automatic Package Update in ntopng

Posted · Add Comment

One of the most useful features in applications, is the ability to Update the application with a matter of click with no need to move to the terminal console. Instruct the system to update the application as a new version is available. We have realised that many of our users missed this feature in ntopng […]

Exploring Physical Network Topologies Using ntopng

Posted · Add Comment

ntop tools are known for monitoring network traffic. However this traffic has to flow on physical networks and thus it is important to understand the physical network layout. LLDP (Link Layer Discovery Protocol) is a network protocol used to dynamically build network topologies and identify network device neighbours. In the latest ntopng dev build (that […]

Spotting Plaintext Information in Network Protocols

Posted · Add Comment

In short: encryption does not always mean that all the information exchanged is really encrypted. Another myth is that many people believe that the equation “encryption = security” holds. Unfortunately this is not true. This slide deck we presented at Sharkfest Europe 19 shows in practical terms what information is sent in clear text in popular […]

ntopng & Suricata: Unifying Visibility with Security

Posted · Add Comment

This week we have presented at Suricon 2019 our work about unifying ntopng with Suricata. https://youtu.be/g7NFjeSQG0c In short: Suricata is a great tool for analysing individual flows but It lacks a GUI It is blind to security threats when they use non-standard ports It is mostly blind to encrypted traffic It does not provide a […]

Using RFC8520 (MUD) to Enforce Hosts Traffic Policies in ntopng

Posted · Add Comment

RFC8520 (Manufacturer Usage Description) specifies what is the intended (from the manufacturer standpoint) network behaviour of a network device. Being it defined in JSON format by the device manufacturer, it can be used for simple single-task devices such as a printer or an access-point where the device communications are simple and well defined. Typically a […]

Merging Infrastructure and Traffic Monitoring: Integrating ntopng with Icinga

Posted · Add Comment

Icinga2 is an open source monitoring system which checks the availability of hosts and services, notifies users of outages and generates performance data for reporting. Thanks to its scalability and extensibility, it has become very popular (as Nagios successor) and suitable to monitor complex environments, even across multiple locations. Although popular, it falls short when […]