Sampled Traffic Analysis by Internet-Exchange-Level Adversaries

coderman coderman at gmail.com
Mon May 28 10:47:22 UTC 2007


On 5/28/07, coderman <coderman at gmail.com> wrote:
> ... is the assumption that inspection at
> OC/WDM layers is too cumbersome/expensive for all but the previously
> mentioned TLA/$gov adversaries?

one more comment that ties into your mention PCIe bus limitations.
previous research on monitoring high speeds links has shown FPGA
devices well suited for header and deep packet inspect at line rates
up to 10GigE for hundreds of snort style  filter rules. this approach
scales in a linear fashion.

i'll try to find some of the papers on this subject; i don't have them
on hand.  coincidentally, many of those involved in such projects seem
to get sucked into the proprietary/classified commercial and
government sectors. *grin*

it's turtles, all the way down...



More information about the tor-talk mailing list