Call us today on

01782 752 369

Packet Capture: How Important is it For Cyber Security?


Our Solution Architect here at KedronUK, Chris Booth, shares his thoughts on the question, packet capture: how important is it for cyber security?

Historically, packet capture has been a tool for troubleshooting complex problems where other information sources are not providing enough detail. Some enterprises have deployed permanent packet capture solutions within data centres but the investment required in storage to provide even short-term data retention deterred many interested users. With 10Gbps (or faster) backbones commonly in use, a busy network will generate Petabytes of data on a weekly basis. Analysing this vast amount of data to provide meaningful insights is also challenging.

However, over the past two to three years a wave of new vendors has seen many businesses investigate traffic based tools, with Gartner naming this sector Network Traffic Analytics (NTA). NTA tools make use of machine learning to automate the analysis of the captured data (be that flow records like NetFlow or raw wire-data) and from this be able to detect/alert on anomalous traffic and events. These data feeds should include both North-South (to/from the Internet) and East-West (internal) traffic.


Whilst attackers will try to hide their presence once a device has been compromised, they have to traverse a network to scan for targets, access resources, attack and/or exfiltrate data. Therefore the network can be seen as the “source of truth”, as it provides empirical evidence.

The Enterprise Management Association (EMA) has recently released a report entitled “Unlocking High Fidelity Security (2019)”. The majority of respondents to the report were IT managers or directors for SME sized companies (1000 to 4999 employees).


Key findings in the report include:

  • Although depending on the type of attack, 60% believed network data is the better source of data for the earliest detection of a breach (compared to endpoint data).
  • The report identifies metadata as a new class of data. Metadata is not the full packet, but the most useful parts, along with additional supporting information which can be deduced from the contents of the packet. For instance, an IP address extracted from a packet can then be geo-located. 65% of respondents identified that metadata is “very valuable” in assisting with investigations, with a further 14% marking it as “extremely valuable”. Metadata can also offer benefits from a retention perspective – by not storing the entire packet, the “lookback” window can be much bigger.
  • Enterprises that were using packet data had the highest confidence they were detecting threats at the reconnaissance of the “Kill Chain”.
  • The report concludes “While network packets do not contain all of the information needed to complete an investigation, the fact that 99% of daily activities across a network makes it easy to understand why companies feel they have a heightened sense of awareness. They can detect issues faster than businesses replying on perimeter, systems, application, and authentication logs”.

Packet data solutions can also provide useful insight for network teams, as they can determinate a range of metrics such as round-trip-times and potential TCP issues like zero windows.

How can KedronUK help?


KedronUK can assist organisations looking to deploy NTA technology for security and/or performance requirements. Our vendor partnerships include both flow data and packet data based NTA solutions, allowing us to pragmatically discuss and demonstrate the benefits and value of these tools.

If you would like any further information, please contact us here.



How To Achieve "Multi-Cloud" Monitoring


Continuing our focus on the challenge of performance monitoring in the Cloud, here David Hock, Director of Research at Infosim, discusses their approach to “Multi-Cloud Monitoring.” We interviewed David Hock and this is what he had to say.

You discuss Multi-Cloud monitoring, what do you mean by that term?

Sourcing of services from different Cloud services providers e.g. Azure, Amazon, Office 365 requires monitoring the services availability, performance and utilization across the different platforms and technologies.

MultiClouds require Cross-Silo monitoring of services for Servers, Storage, distributed, regional Networks, Virtual Systems, Containers, multiple Clouds, App/Web STMs, Enterprise Applications & Infrastructure.

Ensure hybrid services based on legacy infrastructures and systems and multi-provider Cloud services via cross-provider, cross-technology, and cross-silo monitoring in a way, your operations staff can still handle.

Be able to track issues internal and external where they occur and in a reasonable time.

Lots of people when they think about monitoring infrastructure in the Cloud, they think about the tools native in the Cloud providers solutions, why do you think an enterprise should consider a third-party solution such as StableNet?

Cloud SP tools do usually work only per Cloud SP and not cross SP! You need to be able to get a holistic view on your utilized services and not a large number of individual limbs which your operations team needs to correlate manually.

StableNet combines the “passive” monitoring of reading out data from the APIs provided by the respective Cloud providers with “active” probing testing different parameters externally.

Here are two examples below:

Amazon, Azure & Co do “natively” provide information about the CPU usage, the memory usage, the number of disk writes, etc. but not about the actual services running in the virtual machine/Cloud instance. If you want to know how many emails you sent/calendar entries you have/etc., you can ask the Cloud API. If you want to measure how long sending and receiving an email takes or how long adding a contact takes, you need to do external probing – StableNet offers this and combines both worlds/approaches.

If your Cloud provider offers you certain RAM, CPU, etc., the APIs help you to check the actual usage. However, if you want to measure the actual SLA, i.e., whether your service runs smoothly or not, you need external measurements.

How does StableNet differ from other third-party monitoring solutions for Cloud monitoring?

StableNet addresses and ensures hybrid services monitoring based on legacy infrastructures and systems and multi-provider Cloud services via cross-provider, cross-technology, and cross-silo monitoring in a way your operations staff can still handle.

In particular, you do not need yet another tool and graphical user interface but can combine the data in the existing monitoring using renown interfaces for integration.

If a customer has an end-to-end enterprise application service which may consist of elements of public, private and on-premise infrastructure is StableNet able to understand the interrelationship between these components?

StableNet e.g. StableNet Service Analyzer and highly automated StableNet Network Service Analyzer do support analysis tools to model and track cross-provider, cross-technology, and cross-silo infrastructure constellations.

Furthermore, well, known StableNet technologies like the automated root cause analysis, derived measurements, dynamic rule generation can also be used to combine different measurement sources of hybrid Cloud, network, etc.

What is the best way for someone who is interested to see StableNet in action?

Browse our StableNet Web page here.

Watch our Webinar Recordings to see many examples here.

Request an online demo Webinar tailored to your questions from us or our Partners like Kedron here.

KedronUK Partners With Instana to Future Proof Their Customers APM Requirements

KedronUK partners with Instana to future proof their customers APM requirements

KedronUK is a leading network and Application Performance Management (APM) consultancy. They provide their customers with increased visibility and control across their networks and applications infrastructure by combining leading technology, knowledge and service.
Their customers are adopting microservice and serverless technologies as a means to increase the speed at which they can deploy new application functionality and code fixes to their users. The increased speed of delivery and the highly dynamic nature of this new environment brings challenges in maintaining visibility into both overall application performance and individual service performance. KedronUK and their customers found that traditional APM tools required too much manual intervention to keep them in synchronisation with the rapid changes in the production environment. This resulted in critical services not being monitored, additionally, the traditional pricing models of legacy APM tools does not work well with microservices; they are too slow and too expensive.
KedronUK decided to re-evaluate the tooling they offer along with their professional services. Ultimately they selected Instana and signed a strategic partnership.

Why Instana

“With regards to microservices, the main challenges that customers were telling us about with their current APM approach, is that it is too manual to get the dynamic visibility required (which often meant critical services are not being monitored at all) and even then, the pricing models didn’t work – it was too slow and expensive.
KedronUK have spent 9 months reviewing this challenge and thoroughly testing technologies. As a result have signed a strategic partnership with Instana.”
Automation is key to gaining speed through the Continuous Integration / Continuous Development (CI/CD) lifecycle loop. Our customers are already using automation at every stage of the CI/CD process, except for monitoring. Traditional APM tools require too much manual intervention to stay in synchronisation with the ever-changing environment of microservices architectures. Instana brings AI powered automation to APM enabling your DevOps team to concentrate on writing and running code rather than manually configuring monitoring agents, building dashboards and editing health rules. Instana automates it all:
  • Automatic discovery and monitoring of your application services, endpoints and infrastructure
  • Continuous visualisation and performance analysis of your full application stack
  • Every request traced end to end
  • Automatic root cause analysis
Source: DORA 2018 report
Automation the primary enabler for your DevOps organisation to achieve “Elite” levels of software delivery performance. Instana’s automatic monitoring provides immediate feedback on the quality of the latest deployment with 1-second resolution data delivered with only a few seconds lag. Instana’s automatic root cause analysis cuts through alert storm noise to give your DevOps team a clear indication of what needs to be fixed or rolled back.

Kubernetes Insight

Kubernetes is the automation platform for running the microservices that make up your applications in production. The huge benefit provided by its automation is tainted by added complexity and reduced operational visibility with all resources abstracted away. The high level of disconnect from the application code to the hardware it’s running on makes traditional infrastructure monitoring less critical. Consider the levels of abstraction in Kubernetes:
code -> container -> pod -> deployment -> node -> virtual machine
It is considerably more important to understand how the microservices and overarching applications are performing and if they are meeting their desired SLOs. An understanding of the overall health of the Kubernetes backplane is also essential to ensure the highest levels of service quality for your application.
Instana’s Dynamic Graph continually tracks over time each entity’s relationship to every other entity. Therefore at any point in time Instana knows where a service was running, what it calls and what calls it. This includes the complex relationships inside Kubernetes.

Achieve Elite Software Delivery Performance with KedronUK and Instana

Get your CI/CD pipeline to Elite levels of efficiency.
Contact us today to see how Instana gives you immediate visibility into your microservices application.

Factoring in “Hard to Monitor” Applications Within Your IT Monitoring Approach

I spoke to a Vendor recently and my contact there was talking about hard to monitor applications, you know the ones, the ones when you mention them to an APM Vendor they suddenly start to back off, say they’ll get back to you and then they go very quiet! Things like Citrix, SAP, legacy in house developed stuff, etc, etc.

He used the analogy that, a lot of the Performance Monitoring tools available to companies are like GP’s. They have enough knowledge about many different things. But when they spot something in a particular area, then they need to refer you to a specialist (credit to Stuart Kennedy at eG Innovations).

Sometimes with certain types of apps, you need that specialist information, but that doesn’t mean you should have a tool for every key technology in your business.

We don’t need to consult studies (but they do exist) to understand that lots of different performance monitoring and triage tools are hard and expensive to manage and don’t provide an end to end, correlated view.

We consider all this when advising our own Customers and we always start by looking at the following:


  • What is the Customers’ unique mix of application technologies (what needs monitoring and what’s the best method to acquire the data)
  • What are their strategic plans for the future (how do we make sure this investment is future proof)
  • What do they already have in place that they like and trust (what should we keep and integrate with / work alongside)


This helps us to recommend something that has maximum coverage, integrates with the environment and stops the need to “swivel seats” to troubleshoot issues.

So our advice is to make sure you identify the hard to monitor applications, they’re unfortunately usually one of the most important, and make sure the monitoring technologies you have can provide you with deep enough visibility. But also keep in mind the other applications in your environment and try and select a Vendor that covers as many as possible.

We can, of course, help you with all of this and help build and plan your strategy, but if you are going to do it yourself, whilst reducing tools is a good objective, it’s unlikely one Vendor will cover all your bases, so it’s important to plan how that’s going to work - through integration, visualisation layers, workflow, and process.

If you’d like to learn more, we can help you plan to get better visibility, please get in touch here.

Popular Posts

Blog Archive

Our Clients

  • Camden
  • Vodafone
  • SCC
  • timico
  • William Hill