Discussion of Network Data Capture Technology Based on Linux
Jinke Yu · Computer and Modernization · 2010
Currently,traditional capture techniques in Linux are normally based on BPF mechanism,with the continuous improvement of network speed,capture efficiency is declining.This paper introduces a PF_RING capture method based on zero-copy theory in high-speed network,which greatly enhances the system performance through reducing the number of copy data from kernel space to user space;What's more,this paper specifically analyzes how to use it in Linux,at the end,the result of experiment shows that this scheme is feasible.