跳到主要导航 跳到搜索 跳到主要内容

VM-based architecture for network monitoring and analysis

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

A single physical machine provides multiple network monitoring and analysis services (e.g., IDS, QoS) which are installed on the same operating system. Isolation between services is weak and it is difficult to decide the optimum allocation of resources for each service. This paper presents a virtual-machine-based architecture for network traffic monitoring and analysis. Through virtualization, a machine under the architecture logically is divided into one host, one virtual machine monitor (VMM) and multiple virtual machines. The host is responsible for capturing network traffic, and multiplexing it to multiple virtual machines. Each virtual machine hosts a service. VMM performs functions such as isolating services and resolving the conflict between services. Compared with Xen, KVM is chosen as a VMM to implement the architecture. Some network optimizations of the architecture are given. Our evaluation results show that these optimizations can multiplex network traffic received by the host to all services, and improve the data receive performance of services by 67% compared to the architecture in which the traffic is directly transferred to virtual machines, instead of the host, and optimized methods are not adopted.

源语言英语
主期刊名Proceedings of the 9th International Conference for Young Computer Scientists, ICYCS 2008
1395-1400
页数6
DOI
出版状态已出版 - 2008
活动9th International Conference for Young Computer Scientists, ICYCS 2008 - Zhang Jia Jie, Hunan, 中国
期限: 18 11月 200821 11月 2008

出版系列

姓名Proceedings of the 9th International Conference for Young Computer Scientists, ICYCS 2008

会议

会议9th International Conference for Young Computer Scientists, ICYCS 2008
国家/地区中国
Zhang Jia Jie, Hunan
时期18/11/0821/11/08

指纹

探究 'VM-based architecture for network monitoring and analysis' 的科研主题。它们共同构成独一无二的指纹。

引用此