English

D-STREAMON - a NFV-capable distributed framework for network monitoring

Networking and Internet Architecture 2016-08-05 v1

Abstract

Many reasons make NFV an attractive paradigm for IT security: lowers costs, agile operations and better isolation as well as fast security updates, improved incident responses and better level of automation. At the same time, the network threats tend to be increasingly complex and distributed, implying huge traffic scale to be monitored and increasingly strict mitigation delay requirements. Considering the current trend of the networking and the requirements to counteract to the evolution of cyber-threats, it is expected that also network monitoring will move towards NFV based solutions. In this paper, we present Distributed StreaMon (D-StreaMon) an NFV-capable distributed framework for network monitoring. D-StreaMon has been designed to face the above described challenges. It relies on the StreaMon platform, a solution for network monitoring originally designed for traditional middleboxes. An evolution path which migrates StreaMon from middleboxes to Virtual Network Functions (VNFs) is described. The paper reports a performance evaluation of the realized NFV based solution and discusses potential benefits in monitoring tenants' VMs for Service Providers.

Keywords

Cite

@article{arxiv.1608.01377,
  title  = {D-STREAMON - a NFV-capable distributed framework for network monitoring},
  author = {Pier Luigi Ventre and Alberto Caponi and Davide Palmisano and Stefano Salsano and Giuseppe Siracusano and Marco Bonola and Giuseppe Bianchi},
  journal= {arXiv preprint arXiv:1608.01377},
  year   = {2016}
}

Comments

arXiv admin note: text overlap with arXiv:1311.2442

R2 v1 2026-06-22T15:11:45.640Z