Discussion and design of packet capture method in intrusion detecting system
Ximing Li · Jisuanji gongcheng yu sheji · 2006
Two network packet capture method are discussed,SOCKET_PACKET and BPF.As follows,a very wide-used packet capture library Libpcap is introduced in detail,which supports BPF.Its main functions are explained.Then a useful packet capture pro-gramming frame is designed.Snort,which is an open-sourced network intrusion detecting system,captures network packets by Libpcap.After analyzed and explained in detail based on the Snort source code,the mechanism of capturing packets in Snort also obeys the pro-gramming frame we design.Since packet capture method is also used in many other fields,such as network monitoring system,the programming frame has great values to relative researches and developments.