10 Gbit Hardware Packet Filtering Using Commodity Network Adapters

Posted · Add Comment

The promise of filtering packets in hardware is not new. Unfortunately filtering network adapters are pretty expensive, not to mention if they run at 10 Gbit. Furthermore many commercial FPGA-based NICs feature hardware packet filtering, but often require card reconfiguration whenever flow rules are added/removed and have a limited set of rules that can be […]

PF_RING/TNAPI-based 10 Gbit Network Monitoring on Multicore Systems

Posted · Add Comment

Over the past couple of years, PF_RING has been enhanced to exploit innovations in computer hardware. In particular the availability of multicore systems and efficient controllers such as those introduced by Intel with the i7 family (in particular Nehelem and Sandy Bridge) has allowed applications to spread their load across all available processors (24 cores […]

Twelve years of ntop

Posted · Add Comment

The Internet is pretty volatile. As new information become available, the old one disappears. Sometimes we have to look back and see what’s happened in the past years. Shall you be interested in seeing how ntop changed in the past twelve years, you can have a look at this URL, that has several snapshots of […]

Using Genetic Algorithms for Network Intrusion Detection and Integration into nProbe

Posted · Add Comment

Conference: OSCON 2010 Presentation Link: Ignite Track Presented by: Brian Lavender SNORT is popular Network Intrusion Detection System (NIDS) tool that currently uses a custom rule based system to identify attacks. This presentation emphasizes on writing the algorithm to write generate the rules through GA and the integration of them into nProbe, a similar network monitoring […]

Released ntop 4.0

Posted · Add Comment

After a few years of work, this is to announce the availability of ntop 4.0. Major changes include: Partially rewritten ntop processing engine to address reliability and performance Several bugs and stability issues fixed Added better support for IPFIX and NetFlow v9, as well as ntop PEN (Private Enterprise Number) Added support for Cisco ASA […]

Creating 3D Maps using ntop

Posted · Add Comment

Since some time ntop support geolocation. Now courtesy of Ronald W. Henderson it can also display mercator maps and natively integrate with tools such  as Google Earth. These ntop extensions are part of the  NST (Network Security Toolkit) toolkit. For more information please visit the NST Wiki page.

Interview with Luca Deri

Posted · Add Comment

In this video Luca presents the ntop project and gives an outlook of future activities. It was presented during the OSS conference that took place last May in Bolzano. Finally this short interview gives an idea of how ntop can benefit when integrated with commercial applications and vendors such as Würth-Phoenix.