Retina: analyzing 100GbE traffic on commodity hardware
Gerry Wan, Fengchen Gong, Tom Barbette, Zakir Durumeric
Abstract
As network speeds have increased to over 100 Gbps, operators and researchers have lost the ability to easily ask complex questions of reassembled and parsed network traffic. In this paper, we introduce Retina, a software framework that lets users analyze over 100 Gbps of real-world traffic on a single server with no specialized hardware. Retina supports running arbitrary user-defined analysis functions on a wide variety of extensible data representations ranging from raw packets to parsed application-layer handshakes. We introduce a novel filtering mechanism and subscription interface to safely and efficiently process high-speed traffic. Under the hood, Retina implements an efficient data pipeline that strategically discards unneeded traffic and defers expensive processing operations to preserve computation for complex analyses. We present the framework architecture, evaluate its performance on production traffic, and explore several applications. Our experiments show that Retina is capable of running sophisticated analyses at over 100 Gbps on a single commodity server and can support 5--100× higher traffic rates than existing solutions, dramatically reducing the effort to complete investigations on real-world networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2c163314-44b0-45fa-99fc-d579cf29f364Cited by top-tier papers9
- Caravan: Practical Online Learning of In-Network ML Models with Labeling AgentsQizheng Zhang, Ali Imran, Enkeleda Bardhi, Tushar Swamy et al.OSDI 2024 · 18 citations
- Triton: A Flexible Hardware Offloading Architecture for Accelerating Apsara vSwitch in Alibaba CloudXing Li, Xiaochong Jiang, Ye Yang, Lilong Chen et al.SIGCOMM 2024 · 18 citations
- CATO: End-to-End Optimization of ML-Based Traffic Analysis PipelinesGerry Wan, Shinan Liu, Francesco Bronzino, Nick Feamster et al.NSDI 2025 · 16 citations
- Rosebud: Making FPGA-Accelerated Middlebox Development More PleasantMoein Khazraee, Alex Forencich, George C. Papen, Alex C. Snoeren et al.ASPLOS 2023 · 8 citations
- Sidekick: In-Network Assistance for Secure End-to-End Transport ProtocolsGina Yuan, Matthew Sotoudeh, David K. Zhang, Michael Welzl et al.NSDI 2024 · 7 citations
Builds on10
- DROWN: Breaking TLS Using SSLv2Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger et al.USENIX Security 2016 · 192 citations
- The Security Impact of HTTPS InterceptionZakir Durumeric, Zane Ma, Drew Springall, Richard Barnes et al.NDSS 2017 · 161 citations
- New Directions in Automated Traffic AnalysisJordan Holland, Paul Schmitt, Nick Feamster, Prateek MittalCCS 2021 · 122 citations
- TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic CommunicationRalph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar et al.NDSS 2016 · 117 citations
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 97 citations
Related papers
- Iris: Expressive Traffic Analysis for the Modern InternetThea Rossman, Diana Qing, Gerry Wan, Zakir DurumericNSDI 2026 · 2 citations
- SuperFE: A Scalable and Flexible Feature Extractor for ML-based Traffic Analysis ApplicationsMenghao Zhang, Guanyu Li, Cheng Guo, Renyu Yang et al.EuroSys 2025 · 4 citations
- Count-Based Abstractions for Performance Verification of Contention PointsAmir Seyhani, Aarti Gupta, David Walker, Mina Tahmasbi ArashlooNSDI 2026
- HyperCom: Enabling High Performance and Composable Data Structures for Software Network Functions with eBPFBin Yang, Dian Shen, Hanlin Yang, Lunqi Zhao et al.INFOCOM 2025
- GGFAST: Automating Generation of Flexible Network Traffic ClassifiersJulien Piet, Dubem Nwoji, Vern PaxsonSIGCOMM 2023 · 32 citations
