摘要
近几年,随着高速网络的不断发展,网络要处理的实时流量已达千兆,甚至万兆的级别。传统入侵防御系统(Snort),利用Libpcap进行数据包的捕获,在数据包捕获方面已经远远达不到实时处理的要求。讨论并验证PF_RING对入侵防御系统中数据包捕获性能的巨大影响。
In recent years, with the development of high-speed network, the real-time traffic processing has reached Gigabit,sometimes even ten Gi- gabit. The traditional intrusion prevention system (Snort) capture packet by the Libpcap which has been far less than the requirements of real-time processing. Discusses and verifies the huge influence of PF_RING on data packet capture performance of intrusion prevention system.