Retina: analyzing 100GbE traffic on commodity hardware
Gerry Wan, Fengchen Gong, Tom Barbette, Zakir Durumeric
摘要
As network speeds have increased to over 100 Gbps, operators and researchers have lost the ability to easily ask complex questions of reassembled and parsed network traffic. In this paper, we introduce Retina, a software framework that lets users analyze over 100 Gbps of real-world traffic on a single server with no specialized hardware. Retina supports running arbitrary user-defined analysis functions on a wide variety of extensible data representations ranging from raw packets to parsed application-layer handshakes. We introduce a novel filtering mechanism and subscription interface to safely and efficiently process high-speed traffic. Under the hood, Retina implements an efficient data pipeline that strategically discards unneeded traffic and defers expensive processing operations to preserve computation for complex analyses. We present the framework architecture, evaluate its performance on production traffic, and explore several applications. Our experiments show that Retina is capable of running sophisticated analyses at over 100 Gbps on a single commodity server and can support 5--100× higher traffic rates than existing solutions, dramatically reducing the effort to complete investigations on real-world networks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Caravan: Practical Online Learning of In-Network ML Models with Labeling AgentsQizheng Zhang, Ali Imran, Enkeleda Bardhi, Tushar Swamy 等OSDI 2024 · 被引用 18 次
- Triton: A Flexible Hardware Offloading Architecture for Accelerating Apsara vSwitch in Alibaba CloudXing Li, Xiaochong Jiang, Ye Yang, Lilong Chen 等SIGCOMM 2024 · 被引用 18 次
- CATO: End-to-End Optimization of ML-Based Traffic Analysis PipelinesGerry Wan, Shinan Liu, Francesco Bronzino, Nick Feamster 等NSDI 2025 · 被引用 16 次
- Rosebud: Making FPGA-Accelerated Middlebox Development More PleasantMoein Khazraee, Alex Forencich, George C. Papen, Alex C. Snoeren 等ASPLOS 2023 · 被引用 8 次
- Sidekick: In-Network Assistance for Secure End-to-End Transport ProtocolsGina Yuan, Matthew Sotoudeh, David K. Zhang, Michael Welzl 等NSDI 2024 · 被引用 7 次
它引用的顶会 Paper10
- DROWN: Breaking TLS Using SSLv2Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger 等USENIX Security 2016 · 被引用 192 次
- The Security Impact of HTTPS InterceptionZakir Durumeric, Zane Ma, Drew Springall, Richard Barnes 等NDSS 2017 · 被引用 161 次
- New Directions in Automated Traffic AnalysisJordan Holland, Paul Schmitt, Nick Feamster, Prateek MittalCCS 2021 · 被引用 122 次
- TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic CommunicationRalph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar 等NDSS 2016 · 被引用 117 次
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 被引用 97 次
相关 Paper
- Iris: Expressive Traffic Analysis for the Modern InternetThea Rossman, Diana Qing, Gerry Wan, Zakir DurumericNSDI 2026 · 被引用 2 次
- SuperFE: A Scalable and Flexible Feature Extractor for ML-based Traffic Analysis ApplicationsMenghao Zhang, Guanyu Li, Cheng Guo, Renyu Yang 等EuroSys 2025 · 被引用 4 次
- Count-Based Abstractions for Performance Verification of Contention PointsAmir Seyhani, Aarti Gupta, David Walker, Mina Tahmasbi ArashlooNSDI 2026
- HyperCom: Enabling High Performance and Composable Data Structures for Software Network Functions with eBPFBin Yang, Dian Shen, Hanlin Yang, Lunqi Zhao 等INFOCOM 2025
- GGFAST: Automating Generation of Flexible Network Traffic ClassifiersJulien Piet, Dubem Nwoji, Vern PaxsonSIGCOMM 2023 · 被引用 32 次
