摘要
对Intel dpdk数据包捕获技术进行了深入研究,对其优缺点进行了详细的分析。在此基础上,利用dpdk设计并实现了一套基于Linux的数据包捕获系统,成功地将其应用于千兆网络安全防护系统中。使用BPS软件对基于dpdk的网络安全防护系统与基于pf_ring的网络安全防护系统进行仿真分析,结果表明dpdk对整体系统性能的提高成效显著,取得了良好的效果,验证了该方法的可行性。
We analyze the data packet capture technology based on intel dpdk in depth, point out in detail the advantages and disadvantages of dpdk in current development of packet capture technology. We then design and implement a packet capture system based on Linux by dpdk, and apply it to a gigabit network security protection system successfully. Utilizing the BPS software, we simulate our system and the network security protection system based on pf_ring. Simulation results show that dpdk can improve the overall system performance, achieve good effect, thus verifying the feasibility of the proposed method.
出处
《计算机工程与科学》
CSCD
北大核心
2016年第11期2209-2215,共7页
Computer Engineering & Science
基金
陕西省自然科学基础研究计划(2015JM6263)