3 ms·
Your "userland TCP/IP" comment got me excited and I started digging around. I wonder if there's some benefit in trying to port something like TCP Daytona [1,2]
by blutoot 12y ago
Your "userland TCP/IP" comment got me excited and I started digging around. I wonder if there's some benefit in trying to port something like TCP Daytona [1,2] in a high-level language like Python. I'm curious if that will somehow advance the adoption of SDNs.
[1] https://github.com/jamesbw/tcp-daytona https://github.com/jamesbw/tcp-daytona
[2] http://nms.lcs.mit.edu/~kandula/data/daytona.pdf http://nms.lcs.mit.edu/~kandula/data/daytona.pdf
- tedchs 12y agoSoftware Defined Networking is about moving the control plane out of switching/routing devices and into general purpose servers, so that they can make better forwarding decisions such as improved convergence time. In the sense that I understand SDN, I don't think doing TCP in userspace is part of it.
- blutoot 12y agoBut if it can be done easily in a high-level language, then the control plane can be integrated better with a lot of applications written in the same language, no? I was thinking if that can serve as an impetus for SDN adoption.
- corysama 12y agoYou should have a look over here :) https://github.com/SnabbCo/snabbswitch/wiki https://github.com/SnabbCo/snabbswitch/wiki
- tptacek 12y agoLike writing your own emulator, writing a full TCP stack is a project that is intrinsically worth doing. You can probably also come up with real-world applications for it (as a security tester, there are lots of applications for having full control over a TPC stack, regardless of how performant it is), but just having done it offers a huge learning return on a modest investment. You probably don't fully grok what TCP even is until you've made congestion control work.
- eru 12y ago> (as a security tester, there are lots of applications for having full control over a TPC stack, regardless of how performant it is) And sometimes you even want your stack to be slow, eg in a slow loris attack.
- Sami_Lehtinen 12y agoWrong. In these cases you want your stack to be as fast as possible. But you're introducing artificial delay on selected keypoints. If your attack code is slow, then you're basically attacking your self. Target is to consume (a lot if possible) more resources on the target side, than you're using on your own side.
- MagerValp 12y agoI just want to second this, I didn't fully understand networking until I wrote my own stack and threw packets on the wire. A simple stack with ARP/ICMP/IP/UDP can be written in a day and seeing your very own ping packets fly across the globe is pretty damn awesome.