Dissertation > Excellent graduate degree dissertation topics show

PF_RING research and its application in high-speed acquisition of network flow

Author: LiuQing
Tutor: WangFeng;DengHui
School: Kunming University of Science and Technology
Course: Computer Software and Theory
Keywords: Network Stream Capture Zero-Copy PF_RING NAPI
CLC: TP393.06
Type: Master's thesis
Year: 2009
Downloads: 175
Quote: 0
Read: Download Dissertation

Abstract


Network stream capturing means capturing protocol data unit under data link layer through technical means.Network-stream-capturing-related techniques include network interface card (NIC) programming, interruption management, device polling management, direct memory access (DMA), and so on.There are some problems in traditional network stream capturing techniques, including low capturing efficiency, high CPU utilization. Redundant data copy under traditional network stream capturing mode, when the captured packets are transimitted from the networkcard to user space applications, is a kind of reason of the above problems. In high-speed network, especially under the condition of high traffic and short packets, frequent interruptions to the network card will make the system get into a state of interrupted livelock. To adapt to the development of high-speed network and the requirement of high-speed network capturing, zero-copy, device polling and other mechanisms are presented. PF_RING is a new kind of zero-copy solution which provides a method to improve the performance of network stream capturing and donnot need to modify the NIC driver. Device polling mechanism is realized in the mode of NAPI under linux. NAPI is a technology that can improve network process efficiency. The main idea of NAPI is to introduce device polling instead of interruption. Because of many advantages, PF_RING has gradually become the main thecnique in current high-speed network environment.The thesis analyses the PF_RING principle and realization in depth, and points out the advantages and disadvantages of PF_RING mechanism. Based on PF_RING, it realized a new universal interface for developers to program with. PF_RING mechanism is successfully applied to Gigabit Intrusion Detection System, and it successfully enhanced the overall system performance.The main contens includes:(1) Analysis of the PF_RING realization in depth, it mainly includes PF_RING socket architecture and realization, realization of socket in linux kernel, PF_RING key data structures and funtions, and the PF_RING application interfaces:libpfring and libpcap-ring.(2) The thesis constructed a universal interface for developers to make fast development. In that way, it improved memory management and memory allocation. Improved PF_RING gives flexibility for users to add user-customized funtions to solve specific problems.(3) PF_RING mechanism together with NAPI is introduced into GIDS’s data capturing module. The author does some tests about network stream capturing based on PF_RING+NAPI mechanism, and gives out the theoretical analysis.(4) Implement the sensitive word matchment based on PF_PING. It satisfies the request in state security department for its advantages.

Related Dissertations

  1. Web Server Technology Research Based on Zero-copy,TP393.05
  2. Design of Traffic Monitoring System for IPv4/IPv6 Campus Network,TP393.18
  3. Implementation of Gigabit Network Driver and Optimization of Data Transmission Efficiency Based on Linux,TP393.11
  4. Linux environment based on Intel Gigabit Ethernet high-speed packet capture platform for research,TP393.08
  5. Effect of 1α-Hydroxycholecalciferol & Phytase on Phosphorus Metabolism and Regulation of Intestinal NaPi-IIb Gene Expression of Broilers,S831
  6. Research on Key Issues of Lightweight Real-Time Communication,TP393.11
  7. Zero-copy and scan detection technology in Intrusion Detection System,TP393.08
  8. The Network Security Audit System Based on Gigabit Network,TP393.08
  9. Research and Implementation of an Intrusion Detection System Design Scheme,TP393.08
  10. A Research of Zero-Copy Communications Technology in Real Time Environment,TP393.04
  11. Research and Implementation of Packet Classification System in Gigabit Network,TP311.52
  12. Research and Implementation on Linux Packets Capturing of Gigabit Network,TP316.81
  13. DMA_ring Based High Speed Network Packet Capture Architecture and It’s Applications,TP393.08
  14. Design of Network Intrusion Detection System for High-Speed Network,TP393.08
  15. The Design and Implementation of Gigabit Network Packet Capture Platform,TP393.08
  16. Design of Distributed Intrusion Detection System Based on Intelligent Agent,TP393.08
  17. High-speed network system design Clustered Web Cache,TP311.52
  18. Researches on Net Abnormal Monitoring System Based on Linux Kernel,TP393.08
  19. Research on Zero-copy Communication Optimization Techniques in Parallel System,TP338.6
  20. Based on embedded network packet capture key technology research and,TP393.08
  21. Gigabit Ethernet environment, packet capture technology research,TP393.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer networks, test , run
© 2012 www.DissertationTopic.Net  Mobile