Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

An Initial Investigation of the Design Challenges Associated with Reliable 100GigE Packet Capture

Technical Report ·
DOI:https://doi.org/10.2172/1560808· OSTI ID:1560808
Network security researchers often rely on EmulyticsTM to provide a way to evaluate the safety and security of real world systems. This work involves running a large number of virtual machines on a distributed platform to observe how software and hardware will respond to different types of attacks. While EmulyticsTM software such as minimega provide a scalable system for conducting experiments, the sheer volume of network traffic produced in an experiment can easily exceed the rate at which data can be recorded for offline analysis. As such, researchers must perform live analytics, narrow their monitoring scope or accept that they must run an experiment multiple times to capture all the information they require. In support of Sandia's commitment to EmulyticsTM, we are developing new storage components for the Carlin cluster that will enable researchers to capture significantly more network traffic from their experiments. This report provides a summary of Haoda Wang's initial investigation of how new AMD Epyc storage nodes can be adapted to perform packet capture at 100Gbps speeds with minimal loss. This work found that the NVMe storage capabilities of the Epyc architecture are suitable for capturing 100Gbps Ethernet traffic. While capturing traffic with existing libraries was surprisingly challenging, we were able to develop a DPDK-based software tool that recorded network traffic to disk with minimal packet loss.
Research Organization:
Sandia National Laboratories (SNL-CA), Livermore, CA (United States)
Sponsoring Organization:
USDOE National Nuclear Security Administration (NNSA)
DOE Contract Number:
AC04-94AL85000; NA0003525
OSTI ID:
1560808
Report Number(s):
SAND--2019-10319; 679003
Country of Publication:
United States
Language:
English

Similar Records

Comparison of Ring-Buffer-Based Packet Capture Solutions
Technical Report · Thu Oct 01 00:00:00 EDT 2015 · OSTI ID:1225853

OglNet Version 13(SOPHIA)
Software · Wed Aug 08 20:00:00 EDT 2012 · OSTI ID:code-119851

OglNet
Software · Tue Mar 09 19:00:00 EST 2010 · OSTI ID:code-119518

Related Subjects