Made4Flow 2.11.1: NetFlow export for DDoS mitigation, new alerts, and much more

Check out what’s new in Made4Flow 2.11.1: export NetFlow V5, V9, and sFlow to DDoS mitigation platforms, configure alerts by router, and integrate with external systems via REST API. Anyone who operates a medium- or large-scale network knows that traffic visibility isn’t a competitive advantage—it’s a matter of survival. Identifying an ongoing DDoS attack, determining which country the anomalous traffic is coming from, or integrating the NetFlow analyzer with the carrier’s mitigation platform without having to reconfigure routers: these are real day-to-day challenges for NOC and security teams. Version 2.11.1 of Made4Flow, available starting February 27, 2026, addresses precisely these needs. In this article, we detail each new feature and what it accomplishes in practice. What is Made4Flow, and who is this update for? Made4Flow is a NetFlow and sFlow analyzer developed by Made4it for internet service providers, telecom operators, and NOC teams that need detailed visibility into network traffic. It collects flows exported by routers (NetFlow V5, V9, sFlow, IPFIX), applies intelligence to this data, and delivers real-time graphs, alerts, and analytics. This update is particularly relevant for those who: How to Export NetFlow to a DDoS Mitigation Platform — Without Configuring the Routers This is the most eagerly awaited new feature in version 2.11.1 for teams that operate DDoS mitigation platforms. The previous scenario was as follows: to send flows to a third-party mitigation solution, you had to configure the router to export simultaneously to two destinations—the Made4Flow collector and the mitigation platform’s collector. In many environments, this is not simple, is risky, or is simply unfeasible. With Made4Flow’s new flow replicator, the router continues to export flows to Made4Flow as usual. From there, the platform itself replicates and forwards the flows to any external destination in the following formats: Configuration is performed directly through the Made4Flow interface—no downtime, no maintenance window on the routers, and no operational risk. For service providers using solutions such as Wanguard, NSFOCUS, Arbor, or any other platform that uses NetFlow or sFlow, this feature eliminates a complex dependency and speeds up integration. Integrate your DDoS mitigation platform with Made4Flow and replicate NetFlow V5, V9, IPFIX, or sFlow with just one configuration. Threat Analysis: New Visualization to Identify Internal Attacks The Made4Flow Threat Analysis page has been completely redesigned in version 2.11.1. The new layout consolidates the key security metrics on a single screen: total detected threats, suspicious IP addresses, volume of malicious traffic, temporal distribution of incidents, and the main targets. The geographic view of threats has also been enhanced, making it easier to correlate the attack’s origin with its impact on the network. For security teams that need to respond quickly to incidents, this means fewer clicks and more context available at the critical moment. Find out who is launching attacks within your internal network with just ONE CLICK. Sampling Rate and Router Alerts: Stop Analyzing Distorted Data One of the most subtle issues in NetFlow monitoring is sampling rate incompatibility. When the value configured in the analysis tool differs from the one the router is actually using, all traffic graphs become distorted—and the team may make decisions based on incorrect data without realizing it. Version 2.11.1 adds two types of alerts specific to this scenario: Sampling Rate Incompatibility Alert It automatically notifies you when the sampling value configured in Made4Flow differs from what the router is reporting. This is especially useful in environments with multiple routers from different manufacturers (Cisco, Huawei, MikroTik, Juniper), where the sampling pattern may vary. Explicit alerts by router Each router registered in Made4Flow can now have its own active alerts, which are visible directly in the device list and on the edit page. This simplifies management in environments with dozens or hundreds of monitored routers. Get notified before the problem affects your data—set it up in minutes. Traffic by Country and App by Prefix: Real-Time Geographic Visibility For internet service providers and telecom operators, knowing where traffic comes from is just as important as knowing how much traffic there is. A spike originating from a particular country may indicate a volumetric attack in progress; a specific prefix consuming an unusually high amount of bandwidth may signal that a customer’s system has been compromised. Version 2.11.1 adds a new overview screen with traffic charts broken down by: This visibility was available in the raw data, but now it is presented in a native visual format, eliminating the need to export data, cross-reference spreadsheets, or use external tools. See in seconds which country or prefix is generating unusual traffic—and take action before the attack escalates. Aggregation by TCP Flags and Countries: Accurately Detect DDoS Attack Patterns Modern DDoS attacks often masquerade as seemingly normal traffic. Analyzing TCP flags—such as SYN, ACK, or RST floods—is one of the most effective ways to identify malicious traffic before it impacts services. Version 2.11.1 adds new aggregation tabs to the Made4Flow raw data: For security teams investigating incidents, the combination of analysis based on flags and geographic origin is particularly powerful for correlating attack techniques with their source. Identify attacks based on TCP flag patterns and geographic origin in seconds, without external tools. Made4Flow REST API: Integrate with Any System Version 2.11.1 marks the arrival of Made4Flow’s official REST API, opening up the platform for programmatic integrations with other systems. The API offers: In practice, this enables integrations with Zabbix, Grafana, ticketing systems, SIEM, external dashboards, and any system that retrieves data via HTTP. Connect Made4Flow to your ecosystem and automate network data using your own stack. Other improvements in version 2.11.1 Fixes in Version 2.11.1 Frequently Asked Questions About Made4Flow 2.11.1 Can Made4Flow export NetFlow data to my DDoS mitigation platform?Yes. Starting with version 2.11.1, Made4Flow includes a native exporter that replicates flows in NetFlow V5, NetFlow V9, or sFlow to any external destination, without requiring any reconfiguration of the routers. What flow formats does the exporter support?NetFlow V5, NetFlow V9, and sFlow. How does the sampling rate alert work?Made4Flow monitors the sampling rate value reported by each router
What is FlowSpec? How to use FlowSpec to mitigate DDoS attacks?
Essentially, Flowspec is an extension of the BGP protocol that allows routers to apply rules—such as dynamic ACLs or dynamic firewall rules—to specific types of traffic. These rules can be based on a variety of criteria, including source, destination, protocol, port, and so on.
How to Configure NetFlow on Nokia Routers
Today we’ll show you how to configure your Nokia SR OS router to export NetFlow (cflowd). Here we have the Network topology and the Netflow Server information These are the steps required to configure the Nokia SR OS router to export NetFlow v9/v10 via IP Netstream 1 – Configure the NTP server2 – Configure the cflowd parameters with the NetFlow server3 – Configure the interface to enable NetFlow Let’s go through the setup step by step: 1.Configuring the NTP Server It is important to configure an NTP server because flow data uses timestamps based on the router’s time. If the router’s time differs from that of the server, the data will not be time-stamped correctly, resulting in a discrepancy in the information. It is important that you configure at least 2 NTP servers and also your router’s timezone. 2 – Configure the cflowd parameters with the NetFlow server 3- Configure the interface to enable NetFlow Finally, we need to enable NetFlow on the interfaces that will export it. To do this, use the following commands on each interface: Below is the complete configuration of the Router: And enable the following on all interfaces: Detailed description Some additional commands for flow analysis: Conheça o Made4FlowSuporte (WhatsApp)
The Importance of Made4Flow’s New AntiDDoS Decoders
In recent months, our technical team has seen an alarming increase in DDoS attacks of the Carpet bombing type, characterized by intense traffic spikes generally directed at all IP addresses belonging to the ASN. These attacks have negatively impacted network connectivity, presenting an additional challenge in evading detection by many conventional DDoS security systems. Unlike traditional attacks, which focus on a single IP address, these latest attacks show greater sophistication. They send smaller volumes of traffic distributed among several IP addresses, making identifying patterns and distinguishing between legitimate traffic and DDoS attacks a much more complex task. In response to these evolving cybercriminal tactics, the AntiDDoS development team at Made4Flow has taken proactive measures. We recently implemented a series of new decoders to strengthen our detection system. This improvement aims to enhance the accuracy and reliability of our anomaly detection and analysis tool, significantly improving our ability to identify and neutralize more sophisticated DDoS attacks, by taking automated actions that were previously configured in our tool—such as BGP prefix announcements for mitigation or Clean Pipe (scrubbing center) links — in addition to generating reports on the identified attack. In this article, we’ll explore the details of these new Decoders, developed on the basis of extensive Made4Flow analysis and packet captures. These implementations aim to improve the resilience of AntiDDoS, providing a more efficient defense against the complexities of contemporary DDoS attacks. New Decoders from AntiDDoS Made4Flow: • Port 0: Enables the identification of DDoS attacks that use port ZERO in the UDP protocol within an IP packet, whether as the source or destination, since this tactic is frequently used in DDoS amplification attacks.• DNS: A common feature of DDoS attacks is the receipt of packets from DNS servers or hosts responding to DNS requests. These attacks are known as DNS amplification and involve zombie machines (infected machines), servers or assets responding to DNS requests, and the target.• NTP: Another widely used tactic involves attacks using NTP servers. Like DNS-based attacks, these are known as NTP Amplification, exploiting servers or hosts that respond to NTP requests to direct the attack toward its target. Although it is common for devices connected to the network to make NTP queries to keep the date and time up to date, it is possible to improve the detection of DDoS attacks by setting a standard traffic threshold using a decoder.• SSDP: The Simple Service Discovery Protocol (SSDP) can be exploited to send large volumes of packets to the target, abusing device discovery services to amplify the attack and disrupt the target’s connectivity.• IP Fragmentation: Packet fragmentation can occur when a device is unable to send all the necessary information in a single packet. The main issue is that firewall blocks may not be as effective, and large DNS response packets may use fragmented packets. An excess of these packets can impact the network and consume excessive resources from network devices; with this decoder, we can set a threshold and make detection more accurate.• TCP SYN: This decoder plays a key role in detecting attacks known as SYN floods, which involve consuming the resources of servers or device services, rendering them unavailable for use. By setting the correct threshold, we can implement effective preventive measures, preventing this type of attack from occurring and taking actions that result in immediate mitigation.• LDAP: The LDAP decoder plays an important role in identifying DDoS attacks that exploit servers with active LDAP to perform reflections, thereby amplifying malicious traffic.• Chargen: Although it is an older protocol, it is used in some line printers and can be exploited by attackers. Setting a limit for this type of traffic is also important.• TCP and UDP High Ports: In addition to the protocols mentioned above, we have observed in several DDoS attack reports the use of high ports—above port 1024—with the TCP and UDP transport protocols. Therefore, it is important to set limits for these two protocols, making the detection of attacks that use high ports more effective. The addition of new decoders makes DDoS attack detection more efficient by supporting a variety of protocols, protecting against different types of DDoS attacks, minimizing false positives, and enabling more accurate identification of real threats. Acessar a demo do Made4FlowSuporte (WhatsApp)
Internet service providers face a new wave of DDoS attacks
A lack of care in maintaining equipment, services, and IP address block configurations has put ISPs at imminent risk of distributed denial-of-service attacks Internet service providers (ISPs) are at imminent risk of large-scale distributed denial-of-service (DDoS) attacks, largely due to a lack of care in managing equipment, services, and the configuration of IP address blocks. Last year, several Brazilian ISPs faced difficult times as they dealt with DDoS attacks on their infrastructure, a situation that led to numerous posts on social media, as well as coverage in newspapers and on TV shows. Recently, in late February, a new wave of attacks once again hit several ISPs, with numerous reports involving providers in Rio de Janeiro, some of whom have even spoken out publicly, informing customers that they are facing serious problems in providing services due to these attacks. The victim is not necessarily the target Despite the disruptions they cause to internet service operations, DDoS attacks targeting ISPs—contrary to popular belief—do not necessarily target the ISPs themselves. In most cases, the goal of hacker groups is to use these companies’ infrastructure to attack their actual targets, which are usually large multinational corporations. Equipment with inadequate or incorrect configurations, along with human error, are typically factors that facilitate the exploitation and “recruitment” of this infrastructure into the criminal underworld. During large-scale DDoS attacks, victims are typically hit with a high volume of requests originating from thousands—and sometimes tens of thousands—of different sources, usually spread across the globe. Mitigation measures and strategies that rely on human effort to identify the sources of attacks become ineffective in the face of hackers’ enormous firepower, since these attacks originate from thousands of different malicious sources that suddenly flood the victim’s infrastructure. That is why it is best to rely on an Anti-DDoS system. DDoS attacks spread across 181 countries On the 12th of last month, about two weeks before the new wave of DDoS attacks was made public, Hacknet, an artificial neural network designed to identify hacking activity worldwide, identified and mapped a large network of more than 40,000 servers, spread across 181 countries, that were being used to launch DDoS attacks. The news was posted on the website and social media accounts of NetSensor, the company that maintains this neural network, along with a link to download the list of IP addresses being used in the attacks, so that security professionals could take preventive measures to protect themselves. NetSensor reviewed the list of devices that were being exploited, enriched it with additional data, and sent private notifications to the email addresses registered as the contact information for each IP address block. In Brazil, more than 1,000 companies were involved, resulting in more than 1,600 contact emails, in which NetSensor issued the alert, provided information about the device, and made itself available to answer any further questions. The results of the notifications were a negative surprise, with things like: The saddest response came from the person in charge of a provider’s server, who simply wrote: “Please remove my email from the list.” Few companies take this seriously There were also some companies that responded positively to the alert. Some forwarded the case to the person in charge of the device using that IP address; others requested more information about the case; and still others thanked us for the alert and said they would review the case and take the necessary measures. Unfortunately, the percentage of companies that took this more serious and professional approach was around 0.5%. Given this scenario, companies in general need to keep in mind that cybercrime has become much more sophisticated in recent years; it has become highly organized, structured, intelligent, and profitable. Therefore, to be able to confront and defend against these cybercriminals, we must develop techniques and knowledge and make intelligent use of resources that match the level of our attackers. In other words, we must seek out new approaches and technologies capable of helping us defend against emerging threats—threats that we are currently unable to address effectively. Furthermore, the neglect, incompetence, and negligence we see in relation to networks, equipment, and services can no longer be tolerated. Only then will we have a chance of success in confronting the threats that surround us, coming from the dark side of the internet. Source: https://www.cisoadvisor.com.br/provedores-de-internet-enfrentam-nova-onda-de-ataques-ddos/ How to Protect Your Internet Service Provider from DDoS Attacks Just as there are tools used by attackers, we also have tools and methods to protect the service provider. What we need to do is mitigate the attack, which involves protecting the target from DDoS attacks. Made4it has the right tool for you: Made4Flow!With Made4Flow, you can detect attacks and take action to protect your provider. Learn about the benefits of anti-DDoS for internet service providers:
Check out Made4it’s interview for RTI Magazine

Check out our interview for RTI Magazine: Made4it offers a traffic analysis solution Made4it, a Brazilian company headquartered in Apucarana, PR, provides the market with Made4Flow, a network traffic analysis software solution designed for Internet service providers. The product uses information sent via the NetFlow protocol from routers, analyzing parameters such as IP address, port, and source and destination ASN. It is also possible to monitor a specific interface, tracking where the data is being distributed. To assist with Made4Flow’s tasks, the company launched Made4Graph in March. The application manages PPPoE end-users through graphs that show how bandwidth is being used. According to Made4it’s managing partner, Guilherme Ganascim, Made4Graph was developed to address a gap in the market. “As providers begin to grow, companies end up turning to solutions from major manufacturers, a process that can lead to a loss of customer information regarding traffic and connection visibility. To avoid these problems, we developed Made4Graph , which is compatible with routers from brands such as Huawei, Cisco, Juniper, and Mikrotik,” he explains. In addition to Made4Flow and Made4Graph, Made4it offers ICT consulting services covering the technical aspects of an Internet service provider, such as router configurations using BGP; connection activation with carriers; MPLS network design and deployment; configuration and deployment of DNS servers, among other services. With 25 employees, the company currently serves more than 70 providers throughout Brazil. Among its clients are Agility and Tecnet, both from Ceará; Persis Telecom and Delta Telecom, both from Paraná; and Webby Telecom, in São Paulo. See the full version at: http://www.arandanet.com.br/assets/revistas/rti/2019/abril/index.php? (pp. 19 and 20)