• DocumentCode
    3378786
  • Title

    Improving the Performance of Passive Network Monitoring Applications using Locality Buffering

  • Author

    Papadogiannakis, Antonis ; Antoniades, Demetres ; Polychronakis, Michalis ; Markatos, Evangelos P.

  • Author_Institution
    Inst. of Comput. Sci., Found. for Res. & Technol., Heraklion
  • fYear
    2007
  • fDate
    24-26 Oct. 2007
  • Firstpage
    151
  • Lastpage
    157
  • Abstract
    In this paper, we present a novel approach for improving the performance of a large class of CPU and memory intensive passive network monitoring applications, such as intrusion detection systems, traffic characterization applications, and NetFlow export probes. Our approach, called locality buffering, reorders the captured packets by clustering packets with the same destination port, before they are delivered to the monitoring application, resulting to improved code and data locality, and consequently to an overall increase in the packet processing throughput and to a decrease in the packet loss rate. We have implemented locality buffering within the widely used libpcap packet capturing library, which allows existing monitoring applications to transparently benefit from the reordered packet stream without the need to change application code. Our experimental evaluation shows that locality buffering improves significantly the performance of popular applications, such as the Snort IDS, which exhibits a 40% increase in the packet processing throughput and a 60% improvement in packet loss rate.
  • Keywords
    computer network management; monitoring; packet radio networks; safety systems; security of data; Snort IDS; locality buffering; packet loss rate; packet processing; passive network monitoring; Application software; Computerized monitoring; Data structures; Intrusion detection; Libraries; Passive networks; Probes; Prototypes; Telecommunication traffic; Throughput;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Modeling, Analysis, and Simulation of Computer and Telecommunication Systems, 2007. MASCOTS '07. 15th International Symposium on
  • Conference_Location
    Istanbul
  • ISSN
    1526-7539
  • Print_ISBN
    978-1-4244-1853-4
  • Electronic_ISBN
    1526-7539
  • Type

    conf

  • DOI
    10.1109/MASCOTS.2007.28
  • Filename
    4674410