• DocumentCode
    1826510
  • Title

    The Netnice packet filter: bridging the structural mismatches in end-host network control

  • Author

    Okumura, Takashi ; Mosse, Daniel

  • Author_Institution
    Dept. of Comput. Sci., Pittsburgh Univ., PA, USA
  • Volume
    3
  • fYear
    2005
  • fDate
    13-17 March 2005
  • Firstpage
    2091
  • Abstract
    There have been increasing demands for proper monitoring and control in end-host systems, mainly for security and QoS purposes. Nevertheless, existing technologies are insufficient as primitives for end-host security. For example, Berkeley packet filter (BPF), the most popular monitoring infrastructure for many Unix systems, is intended for packet capturing at physical interfaces, and thus, not appropriate for monitoring of applications, which is sometimes critical for system security. This paper presents a simple solution to the problem, utilizing hierarchical virtual network interface (VIF) mechanism. VIF is a new OS abstraction that can be hierarchically structured and attached to OS entities to control their network I/O. We extend VIFs to allow filtering and monitoring of their traffic, and show that it has desirable properties for end-host monitoring and control of traffic. We present our prototype implementation on FreeBSD, and evaluate it qualitatively and quantitatively. Demonstrated advantages include: i) ability to monitor terminating entities at arbitrary granularity, ii) a single consistent framework for both network security and network quality of service, iii) OS independence, iv) efficiency as a control primitive, v) compatibility with BPF interface and its applications, and vi) flexibility for future functional expansion.
  • Keywords
    computer networks; information filters; network interfaces; quality of service; telecommunication control; telecommunication security; telecommunication traffic; Berkeley packet filter; Netnice packet filter; QoS; Unix systems; end-host network control; network quality of service; system security; telecommunication traffic; virtual network interface mechanism; Application software; Band pass filters; Communication system traffic control; Computerized monitoring; Control systems; Inspection; Intelligent networks; Peace technology; Quality of service; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2005. 24th Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings IEEE
  • ISSN
    0743-166X
  • Print_ISBN
    0-7803-8968-9
  • Type

    conf

  • DOI
    10.1109/INFCOM.2005.1498485
  • Filename
    1498485