TNC 24

Old buildings in Rennes, France. Text reads: TNC 2024, Jun 10-14, Rennes. At the bottom is the BENOCS logo.

Next week we are excited to be sponsoring TNC 24 in Rennes and are looking forward to meeting up with the European NREN community once more.

Come visit booth no. 5 to meet Péter György, Hari Jayaraman and Ingmar Poese and discuss how your network is faring.

There might even be some BENOCS swag waiting for you. 😉

Oh, and if you haven’t registered yet for the event, you still can until tomorrow (June 6)!

RIPE 88

A picture of old buildings and a quiet street in Krakow, Poland. The text reads: RIPE 88, May 20-24, Krakow. At the bottom is the BENOCS logo.

It’s (already) that time again – RIPE88 is happening next week in Krakow.  Stephan, our CEO, and Hari (Manager Sales & Strategy) will be joined by our CTO and co-founder Ingmar, as well as Aitor, our product manager.

They are looking forward to catching up with everyone in the RIPE community. If you’d like a meeting set up with them for a chat about BENOCS Anayltics or even just a hot beverage, drop us a line and we’ll sort something out.

TMA 2024

The city of Dresden in the background with the Elbe River in the foreground. The text reads: TMA 2024, May 21-24, Dresden. At the bottom the BENOCS logo.

Next week our senior network engineer, Danny A. Lachos Perez, is off to Dresden to the Network Traffic Measurement and Analysis Conference (TMA 2024). There he will take part in an exciting program surrounding topics on network function virtualization, software-defined networks, content distribution networks, and a whole bunch more.

Get in touch with him or us if you’d like to meet up with him and find out more about any aspects BENOCS Analytics.

ANGA COM

Evening view of a bridge across the Rhein River with the Cologne Cathedral in the background. The text reads: "ANGA COM, May 14-16, Cologne. At the bottom is the BENOCS logo.

It’s time for the broadband and media community to come together again for the 2024 edition of ANGA COM in Cologne. Stephan will be around on day 1 (May 14) and Shankar Mondal will on the ground Wednesday and Thursday.

For questions about traffic analytics in your network, reach out to them directly or send us a message and we’ll set up a meeting.

SANOG 41

Black and white photo of the Gateway to India building, underneath the text: SANOG 41, Apr 29-30, Mumbai. at the bottom is the BENOCS logo.

In a few days, Hari will take off, bound for India and SANOG41, taking place from April 29-30 in Mumbai. We are excited to be sponsoring the event for the very first time and can’t wait to meet up with the South Asian network operations and communications services community.

Will we see you there?

NetCologne chooses BENOCS for its network intelligence

Berlin, Germany, March 12, 2024 – Cologne-based internet provider NetCologne has chosen BENOCS to intelligize the network analytics for its IP-network.

With BENOCS’ help, NetCologne plans to optimize their network traffic, saving costs and further increasing satisfaction among their 485,000-strong customer base throughout the Cologne-Bonn-Aachen region in North Rhine Westphalia.

Michael Adams, Network Engineer at NetCologne: “The tool provided by BENOCS gives us an excellent platform for analyzing and optimizing our network traffic. We are constantly seeing an increasing volume of data produced by our customers and digital applications like AI will only support this development in the future. Therefore, we are looking forward to the new insights we will gather. BENOCS has an outstanding support with implementation and customization. Another reason for our choice was the ongoing development.”

Stephan Schroeder, CEO of BENOCS: “We are honored to have NetCologne on board and are excited to witness exactly how they will utilize BENOCS Analytics to optimize their network traffic. We are confident BENOCS is the perfectly fitting solution for such a modern and thriving company.”

Nomios Germany, experts for IT networks and cyber security in the DACH region (Germany, Austria, Switzerland), will help NetCologne to integrate BENOCS Analytics into their network.

“We are very excited to collaborate with NetCologne, as one of the leading regional internet providers, and BENOCS, with their powerful Analytics tool. This project is a great example of our approach to proactively consult our customers and help them with finding the right solutions and integrating these in their existing infrastructure.” (Thorben Schnittger, Account Manager Nomios Germany)

About NetCologne

With half a million customer connections, NetCologne is one of the largest regional telecommunications providers in Germany. The company offers private and business customers as well as the housing industry future-proof communication technology via its own high-performance fiber-optic network. With around 30,000 kilometres laid and an annual investment in the double-digit million range, the Cologne-based provider is thus driving digitalisation in the region beyond the urban cities.

In addition to traditional telephony, Internet, mobile communications and TV services, the product range also includes professional IT and data center services for companies.

About Nomios

Nomios Germany, a subsidiary of the Nomios Group, is a leading European provider of cyber security and secure network solutions and services. The company develops, secures and manages digital infrastructures around the globe for companies, service providers, telecommunications companies, hospitals and public sector clients of all sizes. With the help of state-of-the-art solutions and services, Nomios Germany creates the basis for a secure and flourishing digital economy and society. By developing, implementing, operating, maintaining and managing best-of-breed solutions, Nomios Germany enables its customers to drive innovation and value creation by bringing agility and flexibility to organizations. Nomios has the most experienced, loyal and certified pool of experts and maintains strategic partnerships with leading technology providers, including Palo Alto Networks, Juniper Networks, Cisco, Fortinet or F5.

About BENOCS

BENOCS GmbH – a spin-off of Deutsche Telekom – is a small company with big plans to revolutionize the way network traffic is managed. Their intelligent and fully automated solutions fit networks of any size and provide ISPs as well as CDNs strategic ways of coping with growing network traffic. With BENOCS Analytics, network operators, transit and wholesale carriers, Hosting and CDNs gain end-to-end visibility of their entire traffic flows. More information at www.benocs.com and on LinkedIn.

Peering Days 2024

In the background an street with old buildings in Krakow. The text reads: Peering Days, March 5-7, 2024. Krakow, PL. At the bottom is the BENOCS logo.

From March 5-7, Péter will be in Krakow for Peering Days and is looking forward to catching up with all of you in the Peering community. Reach out to him or us if you’d like to arrange a meeting – or even just have a coffee.

APRICOT 2024

In the background the city of Bangkok. The text reads: APRICOT 2024, Feb 27 - Mar 1, 2024. Bankok, TH. At the bottom is the BENOCS logo.

Big news! For the first time ever, BENOCS is a proud sponsor of APRICOT! From February 27 until March 1, we will be in Bangkok, Thailand, with our good friends MarvelTec and can’t wait to find out what’s happening in the APNIC community. Stephan and Hari will on the ground all day every day to answer all your burning questions about BENOCS Analytics.

See you then!

NANOG 90

In the background the nighttime skyline of Charlotte, USA. The text reads: NANOG 90, Feb 12-14, 2024. Charlotte, USA. At the bottom is the BENOCS logo.

It’s NANOG time! Next week Hari is off to Charlotte, USA, to attend NANOG 90. Get in touch with us or him directly to arrange a meeting to find out about the latest at BENOCS.

Towards application identification with a novel DNS-based approach

Application-oriented view of traffic sources in the form of a sankey diagram

Today’s internet revolves more around applications and less around networks. An interesting example of this current application-oriented approach is a global outage this year[1]. Nobody remembers that AS13414 reported a down, however, many people remember that X (formerly Twitter) had slowdowns and outages affecting many international users.

In this context, network players (e.g., ISPs) have been trying for decades to understand how application traffic is delivered to end-users. Existing tools are limited and only DPI (Deep Packet Inspection) has been the dominant technology to provide such insight; however, this faces increasing challenges with encryption and scaling.

In this post, we present a BENOCS implementation of a DNS-based correlation framework, called DNS Flow Analyzer (DFA), to annotate and classify the traffic flows with information about applications (e.g., TikTok, Disney+, AmazonPrime, DAZN) and CDN domains (e.g., fastly.net, akamai.net, cloudfront.net). This novel solution allows network providers to expand their traditional network-oriented view with an application-oriented view.

A network-oriented view is not enough

A few decades ago, content providers were building big data centers to serve different Internet-based applications to end-users. In recent years, however, Content Delivery Networks (CDNs) are being used to convey the increasing demands for online applications (including video, gaming, and social networks). These media contents, riding on the top of the network, are known as Over-The-Top applications (OTT-Applications) and they use globally distributed CDNs for sending their content. Currently, large content providers leverage more than one CDN and CDNs also convey traffic of multiple OTT-Applications.

In order to work efficiently, network operators need better knowledge on how traffic from the CDNs and OTT-Applications is delivered to their end-users. However, they have historically focused on obtaining information only about Autonomous Systems (ASes), transit providers, and peers. This network-oriented approach is not enough to answer one key question: how do OTT-Applications use the different CDN domains to distribute their traffic?

An application-oriented approach with DFA

Answering the above question has been a daunting task for network actors. Existing network-focused solutions such as legacy flow tools or DPI are limited in tying traffic information to individual applications. The latter also becomes increasingly inefficient due to encryption and requires a ridiculous amount of hardware, especially working on a large scale.

At BENOCS, we have developed a methodology that includes the analysis, design, and implementation of an application identification system called DNS Flow Analyzer (DFA). DFA annotates and extends the traffic flows with domain name information, so that two new layers are effectively obtained: (i) OTT-Application domain and (ii) CDN domain.

Specifically, we propose a large-scale real-time network data correlation system that uses a set of different data sources (e.g. Netflow, BGP) but mainly it feeds on DNS streams to obtain multi-dimensional traffic information. As a result, we obtain an application-oriented view to identify how a source OTT-Application (e.g. Disney+) is delivering traffic to a network using different CDN domains (e.g., akamai.net, cloudfront.net).

DFA architecture and workflow

The high-level DFA architecture and entire workflow rely on two developed components:

  1. DNS-Netflow Correlation. The output of this component includes extended and correlated data: Netflow and a list of URLs representing a DNS domain name resolution. The sequence of events are:

1.1) Live DNS records are classified in two lists (i) DNS A/4A to map an IP address to a domain name, and (ii) DNS CNAME to map a domain name to another domain name.

1.2) In parallel, live Netflow records are captured at the network ingress interfaces. Each Netflow record contains, among others, timestamp, srcIP, dstIP, bytes, etc.

1.3) DFA looks for the srcIP of a Netflow record in the DNS A/4A list to find the domain name it corresponds to (using getName(IP)). Then, looking at the DNS CNAME list, DFA searches for the previous domain name to find the CNAME it corresponds to (using getName(Name)). The search in the CNAME list continues until no further domain names are found (or a pre-defined loop limit is reached).

Diagram of DFA architecture
  1. CDN-APP Classification. This final output extends the traffic flows with CDN domain and OTT-Application information (including BGP). See the sequence of events below:

2.1) DNS-Netflow data is correlated with BGP to gain more knowledge about the traffic paths (source AS, handover AS, nexthop AS, and destination AS).

2.2) Regarding the CDN domain, getCDN() function uses the first URL in the list of domain names and selects the second-level domain (2LD) and top-level domain (TLD). In case of the latter, this component makes use of the Public Suffix List (PSL) database[2] published by Mozilla.

2.3) This second lookup goes through the list of domain names to obtain an OTT-Application. The getAPP() function uses a URL-APP database to associate a specific domain name or URL to the OTT-Application it belongs to (e.g., dssott.com is for Disney+, pv-cdn.net is for AmazonPrime, etc.). This URL-APP is a customized/curated list that continually evolves as new sources are discovered.

DFA architecture to front end (diagram)

DFA correlates flow and DNS data to see where the network traffic originates. It identifies CDN domains and OTT-Applications within the source AS based on DNS A/CNAME records pairing. This novel and future-proof way to identify applications can be typically used by:

  • Firstline maintenance (NOC) to respond to customer complaints, which are generally about applications, not IP-addresses or ASes.
  • DFA also includes an easy-to-understand multi-dimensional dashboard with a network-oriented view (by default), having the option to unlock two new dimensions to allow the visualization of the traffic flows in an application-oriented view with various OTT-Applications and CDN domains.
Screenshot BENOCS DNS Flow Analyzer

Get in touch with us if you’d like to learn more about DNS Flow Analyzer and see it in action!

[1] https://twitter.com/TwitterSupport/status/1632792942262747136

[2] https://publicsuffix.org/