What makes LOBSTER different from previous traditional monitoring systems?
The first difference is that anonymization is a core component of the LOBSTER framework, since it is essential to address privacy concerns that exist when network data is provided to different parties. The second difference is that LOBSTER explicitly addresses the domain of distributed network monitoring. For instance, it supports primitives to apply the same filters or functions to many different remote sensors at once, to aggregate results, etc. The third difference is that LOBSTER is a passive monitoring system, rather than an active monitoring system which is what most other systems deliver. Translated into UNIX terminology, LOBSTER is a member of the tcpdump family (although much more advanced), while most other systems are related to ping or traceroute. Passive monitoring is hard, as it often involves processing huge amounts of traffic at high link rates. On the other hand, compared to active monitoring it provides very different information. For instance, applications may be pro