PDA

View Full Version : Possible technology that should be in bt3


balding_parrot
06-28-2007, 01:44 AM
Just read this and thought that if they release that technology as open source like they say they will, then i think that it is a must to keep BT at the top of the security distros.






New High-Performance Linux Distro for Security and Monitoring

nPulse announces Catapulta Distribution at ISS World 2007
RESTON, Va., June 12 /PRNewswire/ -- nPulse Networks LLC, a leading integrator of hardware acceleration and open-source tools for network security and monitoring applications, is contributing a new Linux distribution to the public domain.
*(LOGO: Send2Press.com/mediaroom/07-0321-nPulse_72dpi.jpg)
The announcement was made at the recent ISS World Conference in Washington, D.C. by Randy Caldejon, nPulse's President. The new Catapulta distro is the outcome of an internal research project at the company to determine whether a practical wire-speed, gigabit packet capture platform could be built from industry-standard server components for under $4,000.
"For our security, monitoring and intercept customers, 100% visibility of network traffic is critical," said Caldejon, "but we discovered that none of the current Linux distributions is specifically tuned for packet capture. To reach our goal, we had to build Catapulta. Now we plan to make it available for others to use and extend."
The nPulse team experimented with a range of open-source tools such as PF_Ring, a modified libpcap developed by Luca Deri (http://www.ntop.org/), and Streamline, a stream-based communication system by Willem de Bruijn (http://www.few.vu.nl/~wdb/streamline/). An advanced programmable adapter card from Napatech was the eventual solution to the performance and cost goals for the project.
"In fact, we were able to achieve 2Gbps of throughput within our design parameters, with a total CPU utilization of less than 4%," says Peter Shaw, VP of Marketing for nPulse Networks. "Adding Streamline allowed us to achieve line-rate deep packet inspection, comparing over 2000 case-insensitive regular expressions while using less than half of the CPU resource. And we can demonstrate that Catapulta will scale to 10Gbps and beyond."
Catapulta, which incorporates PF_Ring, Streamline and other tools as well as full support for the Napatech network cards, will be available at http://www.catapulta.org/, and the site will also host a user and developer forum to support and enhance the new distro. A full summary of the Catapulta project is available at http://www.npulsenetworks.com/iss.php.
About nPulse Networks
nPulse Networks, a developer and integrator of advanced packet capture solutions for commercial and Government customers, is a global leader in the hardware-acceleration of open-source-based solutions for network security, monitoring, traffic analysis and data management. nPulse is headquartered in Reston, Virginia, and also maintains a development center in Charlottesville, VA. For more information, visit http://www.npulsenetworks.com/.
This release was issued on behalf of the above organization by Send2Press(R), a unit of Neotrope(R). http://www.send2press.com/
DATASOURCE: nPulse Networks LLC
CONTACT: Peter Shaw of nPulse Networks, +1-703-673-0044, ext. 704,
Web site: http://www.npulsenetworks.com/

-=Xploitz=-
06-28-2007, 08:11 PM
New High-Performance Linux Distro for Security and Monitoring

"For our security, monitoring and intercept customers, 100% visibility of network traffic is critical, but we discovered that none of the current Linux distributions is specifically tuned for packet capture.


Bt2 does all this in 1 word....

WIRESHARK!

shamanvirtuel
06-28-2007, 08:19 PM
in two words................................

BackTrack 3.................

hope we do not have to wait too much...thx crew........
and the bugfixes reliz that will come before bt3.....yes bt is enough.....
bt does all packet capture things and could be updated easy via lzm

Sh@m@nVirTuel Serial BackTracker since 1.0

balding_parrot
06-29-2007, 03:06 AM
I was taking it as, current tools are not capable of capturing all the traffic on gigabit networks. But as I don't have a gigabit network to test on I cannot say. But I would still expect that being able to do that at 2-3 times that throughput with only 4% cpu utilisation has got to be better that it is now.

ghaze
06-29-2007, 08:54 AM
An advanced programmable adapter card from Napatech was the eventual solution to the performance and cost goals for the project.

The stat's you mentioned are very impressive. I know, having "watched" a few networks. While the "modified libpcap" may help, I feel the adapter card mentioned above my present a bootleneck. To capture at 2Gbps speeds, you'll need some hardware. Good luck with your average 10/100.

Based on Debian.
Derived from Ubuntu.

If I've got to do it the "debian way", I'm gonna puke. :D

thorin
06-29-2007, 05:00 PM
Bt2 does all this in 1 word....

WIRESHARK!

Including a tool for packet capture does not mean the base OS is tuned to do so.

-=Xploitz=-
06-29-2007, 05:40 PM
Including a tool for packet capture does not mean the base OS is tuned to do so.

Perhaps I read the article a little to fast and just wanted to defend and make BT2 appear as the superior???

balding_parrot
07-01-2007, 10:55 PM
No one was questioning the FACT that BT2 is number 1, and I seriously doubt that anyone here could, or would even attempt to argue to the contrary

The point was about the statement that no OS is optimised for data capture on gigabit+ networks.
And that they are developing an open source solution, which I was saying would be an essential technology to be included in BT3

Hope that clears it up a little


And as for debian, if its open source then surely it could be easily fixed for BT3, that is assuming that their software/tool ever comes to fruition, lives up to the hype and is released open source as they say.

baalpeteor
07-09-2007, 07:07 PM
Bt2 does all this in 1 word....

WIRESHARK!

they are pros im sure they know about wireshark ,as they know about PF_Ring. Wireshark prob isn't good enough and can deliver for their high expectations and needs, and isn't a great solution, but for us it is

-=Xploitz=-
07-09-2007, 07:16 PM
Wireshark ........and isn't a great solution, but for us it is

Ain't that the truth! ;)

jpb2433
07-27-2007, 10:27 PM
Including a tool for packet capture does not mean the base OS is tuned to do so.

What are some suggested tweaks to tune BT2 for Gbps capture speeds?