Linux Symposium, July 13th - 17th, 2009, Montreal, Canada
Centre Mont-Royal
Montreal, Canada
July 13-17, 2009

Register / Login

CFP
Paper Guide

Schedule

Keynotes
Summits
Presentations
Tutorials
BOFS

Venue
Travel & Hotel
Costs & Savings

FAQ

Media
Archives
Contact

Home



PlanetFlow2 - A scalable traffic monitoring system

Sapan Bhatia (sapan.bhatia@gmail.com)

PlanetFlow2 (PF2) is an open-source traffic monitoring system that runs on the over 800 machines of the PlanetLab testbed, tracking about 5 Terabytes of data every day. The goal of PF2 is to match every packet that is transmitted by a PlanetLab node to an execution context that can later be used to answer abuse complaints. Additionally, PF2 offers a variety of forensic tools that can intercept port scans, SYN floods and other types of attacks. A sample of the output of PF2 is available at http://planetflow.planet-lab.org. PF2 consists of four components: a flow logger called fprobe (http://svn.planet-lab.org/browser/fprobe-ulog) that runs on each node, a data gatherer called pdelta (http://svn.planet-lab.org/browser/pdelta) that runs on a central server; the Silk database system (http://svn.planet-lab.org/browser/fprobe-ulog), which actually indexes the data collected in a way to enable efficient queries; and pf2gui (http://svn.planet-lab.org/browser/pf2gui), a GUI that can be used to query the data collected.

In this presentation, we will discuss the design and implementation of PF2 along with benchmarks to evaluate its space, network and CPU footprint. We will also discuss some of our experiences of using it in practice.



Major Sponsors
Minor Sponsors
Wireless Networking

register | call for papers

Copyright © 2009 Linux Symposium Inc. All rights reserved.
Linux is a registered trademark of Linus Torvalds.