|
Project DescriptionNetwork measurement through packet trace collection is an important technique for understanding the fundamental behavior of increasingly complex computer networks. This project aims at exploring a next generation of distributed and high-performance passive measurement infrastructure. The challenges of such systems lie in the large amounts of measurement data that are generated through monitoring of Gigabit links and the need for complex processing to extract relevant information. To alleviate these problems, we have developed a network processor based packet capture system that can preprocess packet traces on the measurement node before storing the trace in a database. The network processor implements several important functions:
To support online anonymization at Gigabit link speed, we have developed a new algorithm that outperforms existing solutions by two orders of magnitude. This anonymization algorithm employs top-hashing and subtree replication to replace online cryptographic computations with simple lookup operations. We have implemented a prototype packet capture node on the Intel IXP2400 network processor and demonstrated its operation at an aggregate data rate of 2 Gbps in hardware. Publications
For a complete list of NSL publications, see the publications page. |
|