The Experts below are selected from a list of 9264 Experts worldwide ranked by ideXlab platform

Greg Regnier - One of the best experts on this subject based on the ideXlab platform.

  • efficient direct user level sockets for an intel spl reg xeon spl trade processor based tcp on load engine
    International Parallel and Distributed Processing Symposium, 2005
    Co-Authors: Vikram A Saletore, P M Stillwell, J A Wiegert, P Cayton, J Gray, Greg Regnier
    Abstract:

    Intel Labs has continued development of the embedded transport acceleration (ETA) software prototype that uses one of the Intel/spl reg/ Xeon/spl trade/ processors in a multi-processor server as a packet processing engine (PPE) that is closely tied to the server's core CPU and memory complex. We have further developed the prototype to provide support for user-level, asynchronous interface for sockets. The direct user socket interface (DUSI) allows user-level applications to interface directly to the PPE using familiar socket commands and semantics. The prototype runs in an asymmetric multiprocessing mode, in that the PPE does not run as a general computing resource for the Host Operating System. We describe the prototype software architecture, the DUSI application interface, and detail our measurement and analysis of some micro-benchmarks. In particular, we measure throughput for transactions and end-to-end latency as the key metrics for the analysis.

  • eta experience with an intel spl reg xeon spl trade processor as a packet processing engine
    High Performance Interconnects, 2003
    Co-Authors: Greg Regnier, Vikram A Saletore, David B Minturn, Gary Mcalpine, Annie Foong
    Abstract:

    The ETA (embedded transport acceleration) project at Intel Research and Development has developed a software prototype that uses one of the Intel/spl reg/ Xeon/spl trade/ processors in a multi-processor server as a packet processing engine. The prototype is used as a vehicle for empirical measurement and analysis of a highly programmable packet processing engine that is closely tied to the server's core CPU and memory complex. The usage model for the prototype is the acceleration of server TCP/IP networking. The ETA prototype runs in an asymmetric multiprocessing mode, in that the packet processing engine does not run as a general computing resource for the Host Operating System. We show an effective method of interfacing the packet processing engine to the Host processors using efficient asynchronous queuing mechanisms. This paper describes the ETA software architecture, the ETA prototype, and details the measurement and analysis that has been performed to date. Test results include running the packet processing engine in single-threaded mode, as well as in multi-threaded mode using Intel's hyper-threading technology (HT). Performance data gathered for network throughput and Host CPU utilization show a significant improvement when compared to the standard TCP/IP networking stack.

Vikram A Saletore - One of the best experts on this subject based on the ideXlab platform.

  • efficient direct user level sockets for an intel spl reg xeon spl trade processor based tcp on load engine
    International Parallel and Distributed Processing Symposium, 2005
    Co-Authors: Vikram A Saletore, P M Stillwell, J A Wiegert, P Cayton, J Gray, Greg Regnier
    Abstract:

    Intel Labs has continued development of the embedded transport acceleration (ETA) software prototype that uses one of the Intel/spl reg/ Xeon/spl trade/ processors in a multi-processor server as a packet processing engine (PPE) that is closely tied to the server's core CPU and memory complex. We have further developed the prototype to provide support for user-level, asynchronous interface for sockets. The direct user socket interface (DUSI) allows user-level applications to interface directly to the PPE using familiar socket commands and semantics. The prototype runs in an asymmetric multiprocessing mode, in that the PPE does not run as a general computing resource for the Host Operating System. We describe the prototype software architecture, the DUSI application interface, and detail our measurement and analysis of some micro-benchmarks. In particular, we measure throughput for transactions and end-to-end latency as the key metrics for the analysis.

  • eta experience with an intel spl reg xeon spl trade processor as a packet processing engine
    High Performance Interconnects, 2003
    Co-Authors: Greg Regnier, Vikram A Saletore, David B Minturn, Gary Mcalpine, Annie Foong
    Abstract:

    The ETA (embedded transport acceleration) project at Intel Research and Development has developed a software prototype that uses one of the Intel/spl reg/ Xeon/spl trade/ processors in a multi-processor server as a packet processing engine. The prototype is used as a vehicle for empirical measurement and analysis of a highly programmable packet processing engine that is closely tied to the server's core CPU and memory complex. The usage model for the prototype is the acceleration of server TCP/IP networking. The ETA prototype runs in an asymmetric multiprocessing mode, in that the packet processing engine does not run as a general computing resource for the Host Operating System. We show an effective method of interfacing the packet processing engine to the Host processors using efficient asynchronous queuing mechanisms. This paper describes the ETA software architecture, the ETA prototype, and details the measurement and analysis that has been performed to date. Test results include running the packet processing engine in single-threaded mode, as well as in multi-threaded mode using Intel's hyper-threading technology (HT). Performance data gathered for network throughput and Host CPU utilization show a significant improvement when compared to the standard TCP/IP networking stack.

Richard A. Kemmerer - One of the best experts on this subject based on the ideXlab platform.

  • A stateful intrusion detection System for World-Wide Web servers
    Proceedings - Annual Computer Security Applications Conference ACSAC, 2003
    Co-Authors: Giovanni Vigna, Vishal Kher, William Van B. Robertson, Richard A. Kemmerer
    Abstract:

    Web servers are ubiquitous, remotely accessible, and often misconfigured. In addition, custom web-based applications may introduce vulnerabilities that are overlooked even by the most security-conscious server administrators. Consequently, web servers are a popular target for hackers. To mitigate the security exposure associated with web servers, intrusion detection Systems are deployed to analyze and screen incoming requests. The goal is to perform early detection of malicious activity and possibly prevent more serious damage to the protected site. Even though intrusion detection is critical for the security of web servers, the intrusion detection Systems available today only perform very simple analyses and are often vulnerable to simple evasion techniques. In addition, most Systems do not provide sophisticated attack languages that allow a System administrator to specify custom, complex attack scenarios to be detected. This paper presents WebSTAT, an intrusion detection System that analyzes web requests looking for evidence of malicious behavior. The System is novel in several ways. First of all, it provides a sophisticated language to describe multi-step attacks in terms of states and transitions. In addition, the modular nature of the System supports the integrated analysis of network traffic sent to the server Host, Operating System-level audit data produced by the server Host, and the access logs produced by the web server. By correlating different streams of events, it is possible to achieve more effective detection of web-based attacks.

Annie Foong - One of the best experts on this subject based on the ideXlab platform.

  • eta experience with an intel spl reg xeon spl trade processor as a packet processing engine
    High Performance Interconnects, 2003
    Co-Authors: Greg Regnier, Vikram A Saletore, David B Minturn, Gary Mcalpine, Annie Foong
    Abstract:

    The ETA (embedded transport acceleration) project at Intel Research and Development has developed a software prototype that uses one of the Intel/spl reg/ Xeon/spl trade/ processors in a multi-processor server as a packet processing engine. The prototype is used as a vehicle for empirical measurement and analysis of a highly programmable packet processing engine that is closely tied to the server's core CPU and memory complex. The usage model for the prototype is the acceleration of server TCP/IP networking. The ETA prototype runs in an asymmetric multiprocessing mode, in that the packet processing engine does not run as a general computing resource for the Host Operating System. We show an effective method of interfacing the packet processing engine to the Host processors using efficient asynchronous queuing mechanisms. This paper describes the ETA software architecture, the ETA prototype, and details the measurement and analysis that has been performed to date. Test results include running the packet processing engine in single-threaded mode, as well as in multi-threaded mode using Intel's hyper-threading technology (HT). Performance data gathered for network throughput and Host CPU utilization show a significant improvement when compared to the standard TCP/IP networking stack.

Giovanni Vigna - One of the best experts on this subject based on the ideXlab platform.

  • A stateful intrusion detection System for World-Wide Web servers
    Proceedings - Annual Computer Security Applications Conference ACSAC, 2003
    Co-Authors: Giovanni Vigna, Vishal Kher, William Van B. Robertson, Richard A. Kemmerer
    Abstract:

    Web servers are ubiquitous, remotely accessible, and often misconfigured. In addition, custom web-based applications may introduce vulnerabilities that are overlooked even by the most security-conscious server administrators. Consequently, web servers are a popular target for hackers. To mitigate the security exposure associated with web servers, intrusion detection Systems are deployed to analyze and screen incoming requests. The goal is to perform early detection of malicious activity and possibly prevent more serious damage to the protected site. Even though intrusion detection is critical for the security of web servers, the intrusion detection Systems available today only perform very simple analyses and are often vulnerable to simple evasion techniques. In addition, most Systems do not provide sophisticated attack languages that allow a System administrator to specify custom, complex attack scenarios to be detected. This paper presents WebSTAT, an intrusion detection System that analyzes web requests looking for evidence of malicious behavior. The System is novel in several ways. First of all, it provides a sophisticated language to describe multi-step attacks in terms of states and transitions. In addition, the modular nature of the System supports the integrated analysis of network traffic sent to the server Host, Operating System-level audit data produced by the server Host, and the access logs produced by the web server. By correlating different streams of events, it is possible to achieve more effective detection of web-based attacks.