03 Oct 2015

Gigascope: High Performance Network Monitoring with an. SQL Interface

1 page acm copy

monitoring ranging from long-term (e.g., monitoring link utilizations, computing traffic matrices) to ad-hoc (e.g., detecting network intrusions, debugging performance problems). many … are complex (e.g., reconstruct TCP/IP sessions), operate over huge volumes of data, and have real-time reporting requirement (e.g., to raise performance or intrusion alert)

Gigascope takes a different approach, provides an SQL interface to the network monitoring system, greatly simplifying the task of managing and interpreting a stream of data.

Gigascope architecture: stream manager + registry

modeling network packets as data streams, crucial to aggressive optimizations such as executing part or all of a query in the NIC.