Publication View

Architecture of a Network Monitor (2003)

Abstract
This paper describes a system for simultaneously monitoring multiple protocols. It performs full linerate capture and implements on-line analysis and compression to record interesting data without loss of information. We accept that the balance must be maintained in such a system between disk-bandwidth, CPU-capacity and datareduction in order to perform monitoring at full line-rate. We present the architecture in detail and measure the performance of our sample implementation, Nprobe.

Publication details
Download http://citeseer.ist.psu.edu/565810.html
Source http://www.cl.cam.ac.uk/Research/SRG/netos/nprobe/publications/pam2003moore.pdf
Publisher unknown
Contributors The Pennsylvania State University CiteSeer Archives
Repository CiteSeer (United States)
Keywords Andrew Moore,James Hall,Christian Kreibich,Euan Harris,Ian Pratt Architecture of a Network Monitor
Language Englisch
Relation oai:CiteSeerPSU:462321, oai:CiteSeerPSU:534798, oai:CiteSeerPSU:201157, oai:CiteSeerPSU:509148, oai:CiteSeerPSU:570247