...
首页> 外文期刊>IEEE Communications Magazine >Traffic Analysis with Off-the-Shelf Hardware: Challenges and Lessons Learned
【24h】

Traffic Analysis with Off-the-Shelf Hardware: Challenges and Lessons Learned

机译:使用现成的硬件进行流量分析:挑战和经验教训

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In recent years, the progress in both hardware and software allows user-space applications to capture packets at 10 Gb/s line rate or more, with cheap COTS hardware. However, processing packets at such rates with software is still far from being trivial. In the literature, this challenge has been extensively studied for network intrusion detection systems, where per-packet operations are easy to parallelize with support of hardware acceleration. Conversely, the scalability of statistical traffic analyzers (STAs) is intrinsically complicated by the need to track per-flow state to collect statistics. This challenge has received less attention so far, and it is the focus of this work. We present and discuss design choices to enable a STA to collects hundreds of per-flow metrics at a multi-10-Gb/s line rate. We leverage a handful of hardware advancements proposed over the last years (e.g., RSS queues, NUMA architecture), and we provide insights on the trade-offs they imply when combined with state-of-the-art packet capture libraries and the multi-process paradigm. We outline the principles to design an optimized STA, and we implement them to engineer DPDKStat, a solution combining the Intel DPDK framework with the traffic analyzer Tstat. Using traces collected from real networks, we demonstrate that DPDKStat achieves 40 Gb/s of aggregated rate with a single COTS PC.
机译:近年来,硬件和软件的进步使得用户空间应用程序可以使用廉价的COTS硬件以10 Gb / s或更高的线速捕获数据包。但是,用软件以这种速率处理数据包仍然不是一件容易的事。在文献中,对于网络入侵检测系统已经对该挑战进行了广泛的研究,在该系统中,每个数据包的操作很容易与硬件加速支持并行化。相反,由于需要跟踪每流状态以收集统计信息,因此统计流量分析器(STA)的可伸缩性从本质上讲是复杂的。到目前为止,这一挑战很少受到关注,这是这项工作的重点。我们介绍并讨论设计选择,以使STA能够以10 Gb / s的线速收集数百个每流指标。我们利用了过去几年提出的一些硬件改进(例如,RSS队列,NUMA体系结构),并结合了最新的数据包捕获库和多种过程范式。我们概述了设计优化STA的原理,并实施它们以设计DPDKStat,该解决方案将Intel DPDK框架与流量分析器Tstat相结合。使用从实际网络收集的跟踪,我们证明了DPDKStat可以通过一台COTS PC达到40 Gb / s的聚合速率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号