Extensible and scalable network monitoring using OpenSAFE

  • Authors:
  • Jeffrey R. Ballard;Ian Rae;Aditya Akella

  • Affiliations:
  • -;-;-

  • Venue:
  • INM/WREN'10 Proceedings of the 2010 internet network management conference on Research on enterprise networking
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Administrators of today's networks are highly interested in monitoring traffic for purposes of collecting statistics, detecting intrusions, and providing forensic evidence. Unfortunately, network size and complexity can make this a daunting task. Aside from the problems in analyzing network traffic for this information--an extremely difficult task itself--a more fundamental problem exists: how to route the traffic for network analysis in a robust, high performance manner that does not impact normal network traffic. Current solutions fail to address these problems in a manner that allows high performance and easy management. In this paper, we propose OpenSAFE, a system for enabling the arbitrary direction of traffic for security monitoring applications at line rates. Additionally, we describe ALARMS, a flow specification language that greatly simplifies management of network monitoring appliances. Finally, we describe a proof-of-concept implementation that we are currently undertaking to monitor traffic across our network.