Technologies and Trends

Technologies and Trends

Breaking Free from Packet Brokers: How to Use nTap/PF_RING ZC for Traffic Aggregation

nTap is a lightweight software-based network tap designed by ntop to simplify remote traffic collection and analysis. Unlike traditional hardware-based packet brokers, nTap lets you capture, forward, and aggregate traffic using pure software—reducing complexity and cost. In this blog post, we’ll walk through: nTap fundamentals (FAQ highlights) Step-by-step configurations for popular use cases Integration with n2disk, nProbe, and ntopng Scaling from low (1 Gbps) to very high-speed (40/100 Gbps) deployments Best practices for performance optimization nTap FAQ Highlights Q: What is the network overhead introduced by nTap?Each captured packet incurs …
ntopng

Introducing ntopng Alerts Graph: Visualize Security Events Like Never Before

Network security analysts often struggle to understand how alerts are connected across different hosts. Traditionally, ntopng displayed flow alerts in a table format, perfect for listing issues, but limited when it comes to spotting patterns or identifying which host is the real problem or victim. Additionally, tabular visualization does not let security analysts or network managers quickly determine which problem to tackle first, causes alert fatigue what are the main network issues, such as brute force attempts, obsolete TLS or SSH version connections, periodic flows etc. These issues are now …
nDPI

Beyond JA3/JA4: Introducing nDPI Traffic Fingerprint

Traffic fingerprinting is a hot topic and we have discussed it several times both in this blog and at conferences. There are various fingerprints techniques and probably most of you know JA3/JA4. Let me do a short recap on the subject in nDPI we support several de-facto fingerprint such a JA4 and additional nDPI-native such as the OS (Operating System) fingerprint. In our research we have realized that in cybersecurity using a single fingerprint (e.g. JA4) leads to too many false positives making it a “nice to have” rather than …
Data Privacy

Export and Archive ClickHouse Flows in ntopng for Regulatory Compliance

Most ntopng users make extensive use of ClickHouse support for storing historical flow data and running analysis on it. ClickHouse is highly optimized and offers a high compression rate (estimated at an average of 60 bytes per flow), allowing for long data retention even with limited storage. However, to comply with regulations such as GDPR, SOX, HIPAA, and PCI DSS, it is often necessary to retain data for extended periods. This is manageable when flow rates are low to moderate, but can require significant disk space when flow rates are …
ntop

New, Fast, Scalable ClickHouse Integration for High-Volume Networks

When it comes to monitoring very large networks and the flows’ cardinality reaches into the billions, the performance of historical data storage and query systems becomes a critical bottleneck. Network operators, analysts, and engineers need to access flow records quickly and reliably, whether for traffic analysis, security investigations, or compliance reporting. When faced with massive datasets, even small inefficiencies in the data pipeline can result in slow queries, high CPU and disk usage, and poor responsiveness. At ntop, our mission is to help users gain visibility into their networks with …