Discussion and design of packet capture method in intrusion detecting system

Ximing Li · Jisuanji gongcheng yu sheji · 2006

Two network packet capture method are discussed,SOCKET_PACKET and BPF.As follows,a very wide-used packet capture library Libpcap is introduced in detail,which supports BPF.Its main functions are explained.Then a useful packet capture pro-gramming frame is designed.Snort,which is an open-sourced network intrusion detecting system,captures network packets by Libpcap.After analyzed and explained in detail based on the Snort source code,the mechanism of capturing packets in Snort also obeys the pro-gramming frame we design.Since packet capture method is also used in many other fields,such as network monitoring system,the programming frame has great values to relative researches and developments.

Read the paper · More papers on PaperTik