<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>http://groups.google.com/group/metaflows</id>
  <title type="text">Metaflows Google Group</title>
  <subtitle type="text">
  Metaflows
  </subtitle>
  <link href="/group/metaflows/feed/atom_v1_0_msgs.xml" rel="self" title="Metaflows feed"/>
  <updated>2012-11-13T08:11:48Z</updated>
  <generator uri="http://groups.google.com" version="1.99">Google Groups</generator>
  <entry>
  <author>
  <name>Livio Ricciulli</name>
  <email>li...@metaflows.com</email>
  </author>
  <updated>2012-11-13T08:11:48Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/def55b15749a9024/d17413db0a02effe?show_docid=d17413db0a02effe</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/def55b15749a9024/d17413db0a02effe?show_docid=d17413db0a02effe"/>
  <title type="text">Re: [MetaFlows] DAQ Compile issue</title>
  <summary type="html" xml:space="preserve">
  I just tried: &lt;br&gt; &lt;p&gt;cd daq-0.6.2; chmod 755 configure; export &lt;br&gt; LD_LIBRARY_PATH=$LD_LIBRARY_PA TH:/usr/local/lib; export &lt;br&gt; LIBS=&#39;-L/usr/local/lib -lpcap -lpthread&#39;; ./configure &lt;br&gt; --disable-nfq-module --disable-ipq-module &lt;br&gt; --with-libpcap-includes=/usr/l ocal/include &lt;br&gt; --with-libpcap-libraries=/usr/ local/lib
  </summary>
  </entry>
  <entry>
  <author>
  <name>Timothy Clarkson</name>
  <email>timothy.j.clark...@gmail.com</email>
  </author>
  <updated>2012-11-13T06:53:55Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/def55b15749a9024/77a545ffd1e68dee?show_docid=77a545ffd1e68dee</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/def55b15749a9024/77a545ffd1e68dee?show_docid=77a545ffd1e68dee"/>
  <title type="text">DAQ Compile issue</title>
  <summary type="html" xml:space="preserve">
  When I pass &lt;br&gt; the --with-libpfring-includes=/usr /local/include/ --with-libpfring-libraries=/us r/local/lib &lt;br&gt; options on the configure command I get back: &lt;br&gt; configure: WARNING: unrecognized options: --with..... &lt;br&gt; I have looked lots of versions and not of them have this option in the &lt;br&gt; configure file - what am I missing ?
  </summary>
  </entry>
  <entry>
  <author>
  <name>Livio Ricciulli</name>
  <email>li...@metaflows.com</email>
  </author>
  <updated>2012-03-14T04:46:43Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/c0436b5c5bb41110/c4f5740346b3d4a1?show_docid=c4f5740346b3d4a1</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/c0436b5c5bb41110/c4f5740346b3d4a1?show_docid=c4f5740346b3d4a1"/>
  <title type="text">Fwd: 回复： 回复： question about IPS with PF_RING</title>
  <summary type="html" xml:space="preserve">
  -------- Original Message -------- &lt;br&gt; Reply-To: s f &amp;lt;fangl...@yahoo.com.cn&amp;gt; &lt;br&gt; To: livio Ricciulli &amp;lt;li...@metaflows.com&amp;gt; &lt;br&gt; hello,livio.I test it successly ,thank you for you help. &lt;br&gt; ______________________________ __ &lt;br&gt; 发件人： livio Ricciulli &amp;lt;li...@metaflows.com&amp;gt; &lt;br&gt; 收件人： s f &amp;lt;fangl...@yahoo.com.cn&amp;gt; &lt;br&gt; 发送日期： 2012年3月14日, 星期三, 上午 1:15
  </summary>
  </entry>
  <entry>
  <author>
  <name>Jaime Nebrera</name>
  <email>jnebr...@gmail.com</email>
  </author>
  <updated>2012-03-07T08:05:50Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/47a035b634df67eb?show_docid=47a035b634df67eb</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/47a035b634df67eb?show_docid=47a035b634df67eb"/>
  <title type="text">Re: [MetaFlows] Drop rate</title>
  <summary type="html" xml:space="preserve">
  Hi Livio, &lt;br&gt; Mmm, I didnt notice. We were using 0,5% and thus were getting much &lt;br&gt; lower results !! &lt;br&gt; Ok &lt;br&gt; I fully agree here &lt;br&gt; As related to public traces, the best listing we were able to find was: &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://sourceforge.net/apps/mediawiki/networkminer/index.php?title=Publicly_available_PCAP_files&quot;&gt;[link]&lt;/a&gt;
  </summary>
  </entry>
  <entry>
  <author>
  <name>livio Ricciulli</name>
  <email>li...@metaflows.com</email>
  </author>
  <updated>2012-03-06T21:19:04Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/383ac06117b44847?show_docid=383ac06117b44847</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/383ac06117b44847?show_docid=383ac06117b44847"/>
  <title type="text">Re: [MetaFlows] Drop rate</title>
  <summary type="html" xml:space="preserve">
  It is arbitrary; but as you can see from our graphs we use &amp;lt;5% as the &lt;br&gt; threshold. &lt;br&gt; The other thing is that you should measure sustained throughput so that &lt;br&gt; you fill up all the buffers. &lt;br&gt; We measure total packets transmitted at a constant rate V.S. total &lt;br&gt; packets processed/forwarded over traces long enough to reduce
  </summary>
  </entry>
  <entry>
  <author>
  <name>Jaime Nebrera</name>
  <email>jnebr...@gmail.com</email>
  </author>
  <updated>2012-03-06T20:56:03Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/dd60d94f3c2a2d7a?show_docid=dd60d94f3c2a2d7a</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/dd60d94f3c2a2d7a?show_docid=dd60d94f3c2a2d7a"/>
  <title type="text">Re: [MetaFlows] Drop rate</title>
  <summary type="html" xml:space="preserve">
  Hi Livio, &lt;br&gt; If packet drop was 0 why stop at that level? &lt;br&gt; Of course we see 0 drop rate at low speeds, I&#39;m asking when should be &lt;br&gt; considered a test has failed, 0,5%, 1%? &lt;br&gt; Enviado desde mi iPhone
  </summary>
  </entry>
  <entry>
  <author>
  <name>livio Ricciulli</name>
  <email>li...@metaflows.com</email>
  </author>
  <updated>2012-03-06T20:40:57Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/87e211a3ea263692?show_docid=87e211a3ea263692</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/87e211a3ea263692?show_docid=87e211a3ea263692"/>
  <title type="text">Re: [MetaFlows] Drop rate</title>
  <summary type="html" xml:space="preserve">
  In some cases we were seeing 0 drop.
  </summary>
  </entry>
  <entry>
  <author>
  <name>Jaime Nebrera</name>
  <email>jnebr...@gmail.com</email>
  </author>
  <updated>2012-03-06T20:14:01Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/20d0288a41eedd9f?show_docid=20d0288a41eedd9f</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/f72de30f61b41ac5/20d0288a41eedd9f?show_docid=20d0288a41eedd9f"/>
  <title type="text">Drop rate</title>
  <summary type="html" xml:space="preserve">
  Hi all, &lt;br&gt; I have noticed snort drops packets even at moderate packet per second rates &lt;br&gt; May I ask the published results what kind of limit to drop rate were &lt;br&gt; considered? &lt;br&gt; Enviado desde mi iPhone
  </summary>
  </entry>
  <entry>
  <author>
  <name>livio</name>
  <email>lricciu...@gmail.com</email>
  </author>
  <updated>2012-02-24T02:44:01Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/4af689c3b8221382/9b5d060dcd830eaa?show_docid=9b5d060dcd830eaa</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/4af689c3b8221382/9b5d060dcd830eaa?show_docid=9b5d060dcd830eaa"/>
  <title type="text">Re: Measuring performance</title>
  <summary type="html" xml:space="preserve">
  The best way to measure pfring performance is to compare the RX PACKET &lt;br&gt; counts from the input interface &lt;br&gt; (or your generator) with the sum of all the Tot Packets counts in the &lt;br&gt; files /proc/net/pf_ring/*eth* with the same &#39;Cluster Id&#39; &lt;br&gt; These proc files are dynamically created and deleted as new processes
  </summary>
  </entry>
  <entry>
  <author>
  <name>four</name>
  <email>sur...@gmail.com</email>
  </author>
  <updated>2012-02-24T00:55:11Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/4af689c3b8221382/5132250d51158e41?show_docid=5132250d51158e41</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/4af689c3b8221382/5132250d51158e41?show_docid=5132250d51158e41"/>
  <title type="text">Measuring performance</title>
  <summary type="html" xml:space="preserve">
  &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.metaflows.com/technology/10-gbps-pf_ring-2/&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; &lt;p&gt;I&#39;ve been reading your blog and following along at home. I have a &lt;br&gt; working snort multithreaded instance using the current SVN of PF_RING. &lt;br&gt; What I can&#39;t seem to figure out is how much traffic my instance is &lt;br&gt; handling. &lt;br&gt; &lt;p&gt;I turned on the snort-stats preprocessor and was looking at the
  </summary>
  </entry>
  <entry>
  <author>
  <name>Jaime Nebrera</name>
  <email>jnebr...@gmail.com</email>
  </author>
  <updated>2012-02-13T11:32:28Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/610a2114d732639e/b74fc12387e2ae86?show_docid=b74fc12387e2ae86</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/610a2114d732639e/b74fc12387e2ae86?show_docid=b74fc12387e2ae86"/>
  <title type="text">Metaflows cutting certain traffic</title>
  <summary type="html" xml:space="preserve">
  Hi all, &lt;br&gt; We have noticed a weird behaviour when we use metaflows. &lt;br&gt; When using metaflows as IPS and enabling SSL or SSH preprocessor, the &lt;br&gt; sytems cuts all encrypted traffic instead of letting it go through after &lt;br&gt; a certain ammount of traffic. &lt;br&gt; Actually, the problem is more or less like this (verified with SSH &amp;amp;
  </summary>
  </entry>
  <entry>
  <author>
  <name>livio</name>
  <email>lricciu...@gmail.com</email>
  </author>
  <updated>2011-12-16T18:14:43Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/3acaaea93099b3b1/39bc0d7538addfab?show_docid=39bc0d7538addfab</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/3acaaea93099b3b1/39bc0d7538addfab?show_docid=39bc0d7538addfab"/>
  <title type="text">Tt takes a cloud to secure a cloud</title>
  <summary type="html" xml:space="preserve">
  If you&#39;re thinking of setting up some of your assets in the cloud, you &lt;br&gt; need to think about how you can do that without compromising your &lt;br&gt; network security monitoring standards and how you can meet regulatory &lt;br&gt; compliance regulations. Even if you run an Intrusion Detection (and/or &lt;br&gt; Prevention) System in your organization or have host-based IDS,
  </summary>
  </entry>
  <entry>
  <author>
  <name>Jaime Nebrera</name>
  <email>jnebr...@gmail.com</email>
  </author>
  <updated>2011-11-29T12:52:32Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/9a77cb74896f8cdb/a866d682194beb9b?show_docid=a866d682194beb9b</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/9a77cb74896f8cdb/a866d682194beb9b?show_docid=a866d682194beb9b"/>
  <title type="text">Warning message</title>
  <summary type="html" xml:space="preserve">
  Hi all, &lt;br&gt; When I start Snort using your great pf_ring enhancement I see the &lt;br&gt; following message: &lt;br&gt; Acquiring network traffic from &amp;quot;eth4:eth5&amp;quot;. &lt;br&gt; Reload thread starting... &lt;br&gt; Reload thread started, thread 0x7f3885b41710 (7081) &lt;br&gt; Checking PID path... &lt;br&gt; PID path stat checked out ok, PID path set to /var/run/ &lt;br&gt; Writing PID &amp;quot;7081&amp;quot; to file &amp;quot;/var/run//snort_eth4:eth5_bpb r1_1.pid&amp;quot;
  </summary>
  </entry>
  <entry>
  <author>
  <name>Livio@metaflows.com</name>
  <email>li...@metaflows.com</email>
  </author>
  <updated>2011-11-16T03:49:15Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/4e36a077730fafbd/a11137a96ff203f2?show_docid=a11137a96ff203f2</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/4e36a077730fafbd/a11137a96ff203f2?show_docid=a11137a96ff203f2"/>
  <title type="text">Re: [MetaFlows] Snort instances and cores information</title>
  <summary type="html" xml:space="preserve">
  I ment remove --daq-mode inline -Q
  </summary>
  </entry>
  <entry>
  <author>
  <name>Livio@metaflows.com</name>
  <email>li...@metaflows.com</email>
  </author>
  <updated>2011-11-16T03:47:10Z</updated>
  <id>http://groups.google.com/group/metaflows/browse_thread/thread/4e36a077730fafbd/29ff4de970f1b759?show_docid=29ff4de970f1b759</id>
  <link href="http://groups.google.com/group/metaflows/browse_thread/thread/4e36a077730fafbd/29ff4de970f1b759?show_docid=29ff4de970f1b759"/>
  <title type="text">Re: [MetaFlows] Snort instances and cores information</title>
  <summary type="html" xml:space="preserve">
  Also, If you only use one interface (passive mode) remove the daq-var inline -Q arguments
  </summary>
  </entry>
</feed>
