Skip to main content

High-speed (10Gb) Packet Inspection

I am involved in a research trying to do a packet inspection on a high-speed (10Gb) [ethernet] network. There are many issues that we have to face.

First, packet drops. We are using software (tools) that requires all packets to be available before the inspection begins. Unfortunately, our network is not clean, there are packet drops. Some packets are missing. This really creates a problem for us.

We could modify the software so that it does not require all packets to be available, or we could "spoof" the missing packets. The idea is that given a timeout, if a packet is not available then we just create a dummy packet. Which one is better (less difficult to do)?

Second, high-speed packet matching library. What kind of library should we use? libnids? tcpflow? libpcap? Not that we are interested in inspecting the content of the packet (payload?). I guess it's something like ngrep but for the whole session (not just one packet).

Sorry if my explanation is not that clear. :)

I am looking for hints, help, pointers...

Comments

rosyidi alwan said…
trully, i was just comment these blog, for introduce my own blog, and i really2 wait for mr.Gbt`s comments to my blog... (i`m so sorry for my very2 poor english and the grammar) :D

Popular posts from this blog

Himbauan Kepada Hacker & Cracker Indonesia & Malaysia

Kepada Hacker & Cracker Indonesia & Malaysia,

Saya mengharapkan anda tidak melakukan penyerangan atau/dan pengrusakan situs-situs Indonesia dan Malaysia.

Saya mengerti bahwa akhir-akhir ini beberapa masalah di dunia nyata membuat kita kesal dan marah. Namun kekesalan tersebut sebaiknya tidak dilimpahkan ke dunia maya (cyberspace). Semestinya sebelum melakukan aksi yang berdampak negatif, kita bisa melakukan langkah-langkah positif seperti melakukan dialog (melalui email, mailing list, bulletin board, blog, dan media elektronik lainnya).

Kita harus ingat bahwa kita hidup bertetangga dan bersaudara. Yang namanya hidup bertetangga pasti mengalami perbedaan pendapat. Mari kita belajar bertetangga dengan baik.

Saya berharap agar kita yang hidup di dunia maya mencontohkan bagaimana kita menyelesaikan permasalahan dengan kepala dingin dan hati yang lapang, sehingga para pemimpin kita di dunia nyata dapat mencontoh penyelesaian damai. Mudah-mudahan mereka dapat lebih arif dan bijaksana da…

Yummy ...

[seafood lamien @ banquet, singapore]

Books, books, books

A snapshot of stacks and shelves of books that I have to read. The stack on the right side is actually on a chair. You can't see the bottom of it. It's a mess. Actually, it shows that I read them.