DocumentCode :
1826510
Title :
The Netnice packet filter: bridging the structural mismatches in end-host network control
Author :
Okumura, Takashi ; Mosse, Daniel
Author_Institution :
Dept. of Comput. Sci., Pittsburgh Univ., PA, USA
Volume :
3
fYear :
2005
fDate :
13-17 March 2005
Firstpage :
2091
Abstract :
There have been increasing demands for proper monitoring and control in end-host systems, mainly for security and QoS purposes. Nevertheless, existing technologies are insufficient as primitives for end-host security. For example, Berkeley packet filter (BPF), the most popular monitoring infrastructure for many Unix systems, is intended for packet capturing at physical interfaces, and thus, not appropriate for monitoring of applications, which is sometimes critical for system security. This paper presents a simple solution to the problem, utilizing hierarchical virtual network interface (VIF) mechanism. VIF is a new OS abstraction that can be hierarchically structured and attached to OS entities to control their network I/O. We extend VIFs to allow filtering and monitoring of their traffic, and show that it has desirable properties for end-host monitoring and control of traffic. We present our prototype implementation on FreeBSD, and evaluate it qualitatively and quantitatively. Demonstrated advantages include: i) ability to monitor terminating entities at arbitrary granularity, ii) a single consistent framework for both network security and network quality of service, iii) OS independence, iv) efficiency as a control primitive, v) compatibility with BPF interface and its applications, and vi) flexibility for future functional expansion.
Keywords :
computer networks; information filters; network interfaces; quality of service; telecommunication control; telecommunication security; telecommunication traffic; Berkeley packet filter; Netnice packet filter; QoS; Unix systems; end-host network control; network quality of service; system security; telecommunication traffic; virtual network interface mechanism; Application software; Band pass filters; Communication system traffic control; Computerized monitoring; Control systems; Inspection; Intelligent networks; Peace technology; Quality of service; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
INFOCOM 2005. 24th Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings IEEE
ISSN :
0743-166X
Print_ISBN :
0-7803-8968-9
Type :
conf
DOI :
10.1109/INFCOM.2005.1498485
Filename :
1498485
Link To Document :
بازگشت