Bottleneck Analysis of Traffic Monitoring using Wireshark

Abes Dabir, Ashraf Matrawy · 2007

This paper looks at the bottlenecks associated with packet capturing using commodity hardware in local area networks (LANs) without losing data. Experiments were carried out using the Wireshark packet sniffer to write captured packets directly to disk in a Fast Ethernet network with various test setups. These experiments involved generating large packets at almost line rate. Various sizes of the kernel level buffer associated with the packet capturing socket were also experimented with. As well, a simple multithreaded design with user level buffers was proposed for the capturing application and experiments were carried out with this solution. The results showed that increasing the buffering at either the kernel level or the application level can significantly improve capturing performance. The best results can be achieved by using a mix of increased kernel socket buffering and a multithreaded capturing application with its own store and hold buffers.

Read the paper · More papers on PaperTik