An Initial Investigation of the Design Challenges Associated with Reliable 100GigE Packet Capture
- Sandia National Lab. (SNL-CA), Livermore, CA (United States)
Network security researchers often rely on EmulyticsTM to provide a way to evaluate the safety and security of real world systems. This work involves running a large number of virtual machines on a distributed platform to observe how software and hardware will respond to different types of attacks. While EmulyticsTM software such as minimega provide a scalable system for conducting experiments, the sheer volume of network traffic produced in an experiment can easily exceed the rate at which data can be recorded for offline analysis. As such, researchers must perform live analytics, narrow their monitoring scope or accept that they must run an experiment multiple times to capture all the information they require. In support of Sandia's commitment to EmulyticsTM, we are developing new storage components for the Carlin cluster that will enable researchers to capture significantly more network traffic from their experiments. This report provides a summary of Haoda Wang's initial investigation of how new AMD Epyc storage nodes can be adapted to perform packet capture at 100Gbps speeds with minimal loss. This work found that the NVMe storage capabilities of the Epyc architecture are suitable for capturing 100Gbps Ethernet traffic. While capturing traffic with existing libraries was surprisingly challenging, we were able to develop a DPDK-based software tool that recorded network traffic to disk with minimal packet loss.
- Research Organization:
- Sandia National Laboratories (SNL-CA), Livermore, CA (United States)
- Sponsoring Organization:
- USDOE National Nuclear Security Administration (NNSA)
- DOE Contract Number:
- AC04-94AL85000; NA0003525
- OSTI ID:
- 1560808
- Report Number(s):
- SAND--2019-10319; 679003
- Country of Publication:
- United States
- Language:
- English
Similar Records
Comparison of Ring-Buffer-Based Packet Capture Solutions
OglNet Version 13(SOPHIA)
OglNet
Technical Report
·
Thu Oct 01 00:00:00 EDT 2015
·
OSTI ID:1225853
OglNet Version 13(SOPHIA)
Software
·
Wed Aug 08 20:00:00 EDT 2012
·
OSTI ID:code-119851
OglNet
Software
·
Tue Mar 09 19:00:00 EST 2010
·
OSTI ID:code-119518