The wide availability of cheap and effective commodity PC hardware has driven the development of versatile traffic monitoring software such as protocol analyzers, traffic characterizers and intrusion detection systems. Most of them are designed to run on general purpose architectures and are based on the well-known libpcap API, which has rapidly become a de facto standard. Although many improvements have been applied to packet capturing software, it still suffers from several performance flaws, mainly due to the underlying hardware bottlenecks. To overcome these issues, this paper proposes a system architecture, which combines the high performance of a Network Processor card with the flexibility of software-based solutions. It allows for removing most part of the hardware limitations exhibited by a purely PC-based architecture, while preserving the full compliance to any software applications based on libpcap. In addition, the proposed system enables the use of monitoring applications at the wire speed, with the possibility of on-the-fly data processing. The system performance has been thoroughly assessed: the results show that it clearly outperforms the previous PC-based solutions in terms of packet capturing power, while the timestamping accuracy is as good as that achieved by DAG cards. Copyright © 2009 John Wiley & Sons, Ltd. The availability of cheap and effective commodity PC hardware has driven the development of traffic monitoring software designed to run on general purpose architectures. However, it suffers from several performance flaws, mainly due to the underlying hardware bottlenecks. To overcome these issues, a system architecture is proposed which combines the high performance of a Network Processor card with the flexibility of software based solutions, thus enabling the use of monitoring applications at the wire speed with the possibility of on-the-fly data processing. Copyright © 2009 John Wiley & Sons, Ltd.
The extensive availability of cost effective commodity PC hardware pushed the development of flexible and versatile traffic monitoring software such as protocol analyzers, protocol dissectors, traffic sniffers, traffic characterizers and IDSs (Intrusion Detection Systems). The largest part of these pieces of software is based on the well known libpcap API, which in the last few years has become a de facto standard for PC based packet capturing. Many improvements have been applied to this library but it still suffers from several performance flaws that are due not to the software itself but rather to the underlying hardware bottlenecks. In this paper we present a new traffic monitoring device, implemented by an Intel IXP2400 Network Processor PCI-X card connected to a gigabit Ethernet LAN hosting a cluster of common personal computers running any libpcap based application. This architecture outperforms the previous solutions in terms of packet capturing power and timestamp accuracy.
The extensive availability of cost effective commodity PC hardware pushed the development of flexible and versatile traffic monitoring software such as protocol anal yzers, protocol dissectors, traffic sniffers, traffic characterizers and IDSs (Intrusion Detection Systems). The largest part of these pieces of software is based on the well known libpcap API, which in the last few years has become a de facto standard for PC based packet capturing. Many improvements have been applied to this library but it still suffers from several performance flaws; these flaws arenot generated by the software itself but by the underlying hardware bottlenecks. In this paper we present the architecture and the implementation design of a new traffic monitoring device, implemented by an Intel IXP2400 network processor PCI-X card connected to a gigabit ethernet LAN hosting a cluster of common persona l computers running any libpcap based application. Since this is mainly an architectural work, only very preliminary experimental results are presented, while every design choice is justified from a theoretical point of view.
Passive network monitoring is required for the operation and maintenance of communication networks as well as to detect frauds and attacks. Typically, raw packet-level traffic traces are collected using suitable traffic probe devices and fed to monitoring applications (IDSs, antivirus, etc.) for analysis, with potential risks for the legitimate privacy rights of the customers. This paper aims to discuss the technical feasibility and the underlying research challenges of a two-tiered privacy-preserving network monitoring system, where carefully designed data protection mechanisms can coexist with suitably adapted monitoring applications.
The paper presents the architecture of a measurement system designed to reside into DiffServ/MPLS Linux based routers. The goal of this research is to develop an open source software product to be used for management purposes and to be integrated in the network control plane in order to automate resource allocation, admission control and Traffic Engineering functionalities. The system is designed to be flexible, configurable and modular and each module has been implemented in order to minimize the impact of the system itself on the traffic dynamics. The output of the system is a sequence of measurements that report the amount of per-PHB and per-LSP traffic offered to the router over a configurable time window. The system allows to perform prediction on the future traffic activity as well as trigger asynchronous threshold crossing events. The system has proven to be reliable as it passed several functional tests. Preliminary experimental results have shown that the output of the system accurately captures the traffic patterns offered to the router.
Stefano Giordano合作论文数Dept. of Information Engineering;University of Pisa4