Using Topological Mapping to Manage & Secure Large Networks NANOG23: October 23, 2001 karl@lumeta.com
Lumeta: What we do Connect to a client network, send and receive lots of packets, and deliver maps and data It all started with mapping the Internet...
The Internet
Why is this Important? Images convey more information in less “real estate.” Maps call attention to anomalies more clearly. You can’t secure what you can’t manage. You can’t manage what you can’t define.
A Typical Intranet
Specifics for ISPs Order Matters: For an ISP, the network is their business The business portions of ISP networks are highly organized and methodically laid out Yet, there are still organic components, e.g., the corporate intranet
What an ISP Looks Like
What can be Found? Undocumented infrastructure or incomplete mergers Legacy connections to forgotten business partners or spun off business units Mismanaged firewalls and routers
Routing Table Errors
Incomplete Divestitures
Another Look at the ISP
Conclusion Network maps condense complex structural information into a manageable form Topological features can readily point out anomalies Assertion: Any large network can be improved by being mapped