Dissertation > Excellent graduate degree dissertation topics show

Gigabit Ethernet environment, packet capture technology research

Author: HanRuBing
Tutor: LiHanJu
School: Huazhong University of Science and Technology
Course: Information Security
Keywords: Gigabit Ethernet Packet capture Zero-copy Device polling Socket ring buffer
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 84
Quote: 5
Read: Download Dissertation

Abstract


With the continuous growth of Internet bandwidth , network security technology is facing increasingly heavy data monitoring tasks . The passive packet capture technology in the field of network security is the basis for all monitoring applications , such as network testing software , a variety of intrusion detection systems, firewalls, and network debugging and other applications , are required packet capture technology . Due to the current popular operating system defects (Linux , etc. ) , in a Gigabit Ethernet environment packet capture applications tend to perform poorly , packet loss rate is quite serious . A method of receiving and processing data packets NIC way by the interrupt mode to device polling mode methods have been proposed to solve the Gigabit Ethernet packet capture environment issues . Based on this idea , NAPI ( based on polling mechanism of network data processing mechanisms ) techniques have been proposed to achieve this improvement: the technology through a hardware interrupt to start polling mechanism , makes the CPU processing interrupt respect greatly reduced the burden . On this basis , Luca Deri et al proposed a new method : PF_RING technology, which combines the device polling mechanism , NAPI technology and zero-copy technology . By PF_RING technology, even a conventional PC, but also in Gigabit Ethernet environments to capture all the data without packet loss . PF_RING to versatility as the goal, through the package makes use of Socket ( Socket ) function and the libpcap ( packet capture library dedicated ) function application can directly use the technology . But the technology exists PF_RING large memory and data copying and other issues. Because PF_RING applicability requirements, so that the program did not really achieve zero-copy . To solve this problem, a modification in PF_RING made ​​on the basis of the program : including cancellation ring buffer memory mapped directly via DMA (direct memory access ) caching . Modified PF_RING although not as good as the hardware versatility original PF_RING, but the true zero copy . Experiments show that the modified PF_RING, under the high-speed network packet capture application , the performance is further improved, with better efficiency of resource use . Modification program is also proposed for the future in this area better high-speed network packet capture program to make preparations.

Related Dissertations

  1. The Design of the Dual-Camera High-Speed Synchronous Capturing System Based on Gigabit Ethernet,TP274.2
  2. The Implementation of Embedded TCP/IP Stack Based on the Method of Operating System Driver,TN915.04
  3. Interface Driver Design and Realization of Mutiple-dsp Parallel Processing for Route Planning System,TP368.12
  4. Design and Implementation of Embedded Eye Tracking System Based on DSP,TP368.1
  5. PCI-E interface -based data acquisition system FPGA Design and Implementation,TN791
  6. Virtual file system fragmentation zero-copy collation system,TP316.7
  7. Distributed Real-Time Detection System Research and Implementation of P2P,TP393.02
  8. PCI-E interface -based data acquisition system software design and implementation,TP274.2
  9. Passive Network Measurements for Troubleshooting and Testing,TP393.06
  10. Design and Realization of Color Doppler Ultrasound Signal Process System Based on DSP Array and Gigabit Ethernet Interface,TN911.7
  11. Design of Full-color Outdoor LED Large Screen Control System Based on FPGA,TN873
  12. Comprehensive host -based firewalls and intrusion detection security system,TP393.08
  13. Research on High-Speed IP Packet Capture Technology Based on Multi-core Architecture,TP393.08
  14. Research and Realize of Network Monitoring Based on Data Packet Capture,TP393.08
  15. The Design and Implementation of the full analysis mode network billing system,TP311.52
  16. High-speed Network Data Capture and Parallel Processing on Multi-Core Platform,TP393.08
  17. The Performance Optimization of Network Intrusion Detection Systems for High-Speed Networks,TP393.08
  18. Research and Implementation of Intrusion Detection Techniques Based on Double Zero Copy Model for High-Speed Network,TP393.08
  19. Gigabit Ethernet framing module design and implementation,TP393.11
  20. Design and Implementatioin of BT Traffic Monitoring System,TP393.093
  21. Web Server Technology Research Based on Zero-copy,TP393.05

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile