Safety and Performance in an Open Packet Monitoring Architecture

Kostas G. Anagnostakis, Sotiris Ioannidis, Stefan Miltchev, John P. A. Ioannidis, Michael B. Greenwald, Jonathan M. Smith · ScholarlyCommons (University of Pennsylvania) · 2002

Abstract Packet monitoring arguably needs the flexibility of open architectures and active networking. A sig-nificant challenge in the design of open packet monitoring systems is how to effectively strike a balance between flexibility, safety and performance. In this paper we investigate the performance of FLAME,a system that emphasizes flexibility by allowing applications to execute arbitrary code for each packet received. Our system attempts to achieve high performance without sacrificing safety by combining theuse of a type-safe language, lightweight run-time checks, and fine-grained policy restrictions. Experiments with our prototype implementation demonstrate the ability of our system to support representativeapplication workloads on Gbit/s links. Such performance indicates the overall efficiency of our approach; more narrowly targeted experiments demonstrate that the overhead required to provide safety isacceptable. 1

Read the paper · More papers on PaperTik