CERT YAF
• Software
Publisher
Software Engineering Institute
Abstract
YAF, Yet Another Flowmeter, processes packet data from PCAP(3) dump files and exports the flows to IPFIX Collecting Processes or an IPFIX-based file format.
YAF, Yet Another Flowmeter, processes packet data from PCAP(3) dump files and exports the flows to IPFIX Collecting Processes or an IPFIX-based file format.CERT YAF was originally intended as an experimental implementation for tracking developments in the IETF IPFIX working group, specifically bidirectional flow representation, archival storage formats, and structured data export with Deep Packet Inspection.
CERT YAF is designed to perform acceptably as a flow sensor on any network on which white-box flow collection with commodity hardware is appropriate. It can be used on specialty hardware when scalability and performance are a concern. The CERT yaf toolchain consists of two primary tools: yaf itself, and yafscii.