Sampled Traffic Analysis by Internet-Exchange-Level Adversaries
coderman
coderman at gmail.com
Mon May 28 10:47:22 UTC 2007
On 5/28/07, coderman <coderman at gmail.com> wrote:
> ... is the assumption that inspection at
> OC/WDM layers is too cumbersome/expensive for all but the previously
> mentioned TLA/$gov adversaries?
one more comment that ties into your mention PCIe bus limitations.
previous research on monitoring high speeds links has shown FPGA
devices well suited for header and deep packet inspect at line rates
up to 10GigE for hundreds of snort style filter rules. this approach
scales in a linear fashion.
i'll try to find some of the papers on this subject; i don't have them
on hand. coincidentally, many of those involved in such projects seem
to get sucked into the proprietary/classified commercial and
government sectors. *grin*
it's turtles, all the way down...
More information about the tor-talk
mailing list