• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

计算机工程与科学

• 论文 • 上一篇    下一篇

基于dpdk的高效数据包捕获技术分析与应用

赵宁1,谢淑翠2   

  1. (1.西安邮电大学通信学院,陕西 西安 710061;2.西安邮电大学理学院,陕西 西安 710061)
  • 收稿日期:2015-06-29 修回日期:2015-11-05 出版日期:2016-11-25 发布日期:2016-11-25
  • 基金资助:

    陕西省自然科学基础研究计划(2015JM6263)

Analysis and application of the high performance data
packet capture technology based on dpdk

ZHAO Ning1,XIE Shucui2   

  1. (1.School of Communication Engineering,Xi’an University of Posts and Telecommunications,Xi’an 710061;
    2.School of Science,Xi’an University of Posts and Telecommunications,Xi’an 710061,China)

     
  • Received:2015-06-29 Revised:2015-11-05 Online:2016-11-25 Published:2016-11-25

摘要:

对Intel dpdk数据包捕获技术进行了深入研究,对其优缺点进行了详细的分析。在此基础上,利用dpdk设计并实现了一套基于Linux的数据包捕获系统,成功地将其应用于千兆网络安全防护系统中。使用BPS软件对基于dpdk的网络安全防护系统与基于pf_ring的网络安全防护系统进行仿真分析,结果表明dpdk对整体系统性能的提高成效显著,取得了良好的效果,验证了该方法的可行性。

关键词: 数据包捕获, dpdk, 网络安全防护系统, BPS, pf_ring

Abstract:

We analyze the data packet capture technology based on intel dpdk in depth, point out in detail the advantages and disadvantages of dpdk in current development of packet capture technology. We then design and implement a packet capture system based on Linux by dpdk, and apply it to a gigabit network security protection system successfully. Utilizing the BPS software, we simulate our system and the network security protection system based on pf_ring. Simulation results show that dpdk can improve the overall system performance, achieve good effect, thus  verifying the feasibility of the proposed method.

Key words: data packet capture, dpdk, network security protection system, BPS, pf_ring