Network administrators lack the tools they need to understand and react to their changing networks. This makes it difficult for them to make informed, timely decisions regarding network management, capacity planning, and security. These challenges will only increase as networks continue to gain in throughput, become more complex, and encrypt more and more of their traffic.This paper describes the Passive Network Appliance, or PNA, which is our proposed solution to this problem. The PNA provides snapshots of network behavior through time, in a cost-effective manner. The PNA is implemented on commodity hardware and can enforce network policy in realtime at the granularity of network frame arrival. This paper describes the system, and its evaluation in laboratory and real-world deployments.
Abstract-Network speeds are increasing and processor core counts rise while processor clock rates stagnate. This has led to both packet processing applications distributing their workload over several cores and virtualization of physical systems also using multiple cores. However, these two concepts are at odds with each other as both must take full advantage of multi-core systems for desirable performance.In this paper, we look at the performance considerations of dealing with 10 Gbps traffic rates in worst case loads using a bare-metal system and a virtual appliance model and several difference packet capture methods. We also discuss potential ideas to improve the performance of these virtual systems.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.