|
Centre Mont-Royal
Montreal, Canada July 13-17, 2009 |
|||||
|
Keynotes
Venue
|
PlanetFlow2 - A scalable traffic monitoring systemSapan Bhatia (sapan.bhatia@gmail.com)PlanetFlow2 (PF2) is an open-source traffic monitoring system that runs on the over 800 machines of the PlanetLab testbed, tracking about 5 Terabytes of data every day. The goal of PF2 is to match every packet that is transmitted by a PlanetLab node to an execution context that can later be used to answer abuse complaints. Additionally, PF2 offers a variety of forensic tools that can intercept port scans, SYN floods and other types of attacks. A sample of the output of PF2 is available at http://planetflow.planet-lab.org. PF2 consists of four components: a flow logger called fprobe (http://svn.planet-lab.org/browser/fprobe-ulog) that runs on each node, a data gatherer called pdelta (http://svn.planet-lab.org/browser/pdelta) that runs on a central server; the Silk database system (http://svn.planet-lab.org/browser/fprobe-ulog), which actually indexes the data collected in a way to enable efficient queries; and pf2gui (http://svn.planet-lab.org/browser/pf2gui), a GUI that can be used to query the data collected. In this presentation, we will discuss the design and implementation of PF2 along with benchmarks to evaluate its space, network and CPU footprint. We will also discuss some of our experiences of using it in practice. |
| |||||||||||||||
|
Copyright © 2009 Linux Symposium Inc. All rights reserved. |
|||||||||||||||||