pktd: A Packet Capture and Injection Daemon

نویسندگان

  • José Marı́a González
  • Vern Paxson
چکیده

Administrators can be highly reluctant to run foreign measurement tools on their hosts because (a) such tools frequently require privileged execution in order to transmit customized measurement packets and/or to passively capture network traffic, and (b) the administrators lack mechanisms to control the rate, duration, type, destination, and contents of traffic generated by the measurements. We present preliminary work on pktd, a packet capture and injection multiplexer daemon that provides controlled, finegrained access to the network device. On systems running pktd, client measurement tools are not given direct access to the network device. Instead, they are obliged to request access via pktd. By providing administrators control over the pktd mechanism, they can easily and securely enforce their desired policies concerning which clients should be granted which sorts of network access capabilities. Thus, pktd can serve as the sole trusted, privileged entity for conducting measurements, eliminating the need for administrators to vet the individual measurement tools.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Implementation and Validation of Multicast-Enabled Landmark Ad-hoc Routing (M-LANMAR) Protocol

In this paper, we investigate the performance of M-LANMAR by implementing the protocol in Linux platform. With existing Linux implementation of ODMRP, we compare the performance of M-LANMAR to that of ODMRP. The two components constitute MLANMAR implementation: routing and packet forwarding. Because M-LANMAR requires packet manipulations (e.g., the source duplicates the packet and each landmark...

متن کامل

Cloning and expression of an intron-deleted phage T4 td gene.

The 1017-bp intron within the cloned phage T4 td gene was deleted by oligonucleotide-directed mutagenesis. Induction of thymidylate synthase activity and mature td mRNA from this intronless construct (pKTd delta I) was compared both in vivo and in vitro with expression from plasmids bearing td genes in which the introns contain either no change (pKTd2), an XbaI linker inserted about 200 nucleot...

متن کامل

Further daemon detection experiments

The experiments on detection of daemons captured into geocentric orbits, which are based on the postulated fast decay of daemon-containing nuclei, have been continued. By properly varying the experimental parameters, it has become possible to reveal and formulate some relations governing the interaction of daemons with matter. Among them are, for instance, the emission of energetic Auger-type e...

متن کامل

Deterministic Fault Injection of Distributed Systems

Ensuring that a system meets its prescribed speciication is a growing challenge that confronts software developers and system engineers. Meeting this challenge is particularly important for distributed systems with strict dependability and timeliness constraints. This paper presents a technique, called script-driven probing and fault injection, for the evaluation and validation of dependable pr...

متن کامل

SSH and Intrusion Detection

Widespread use of the SSH protocol greatly reduces the risk of remote computer access by encoding the transmission of clear text usernames and passwords. Prior to the use of SSH, packet sniffing, which allows malicious users to watch for the login process in the clear text packet traffic on a network segment, was an easy method for a malicious user to gain unauthorized access to a machine. Unfo...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010