通信学报 ›› 2014, Vol. 35 ›› Issue (Z1): 46-51.doi: 10.3969/j.issn.1000-436x.2014.z1.010

• 网络新技术及其应用 • 上一篇    下一篇

面向应急响应的高速网络流量采集设计与实现

马亚洲,龚俭,杨望   

  1. 东南大学 计算机科学与工程学院,江苏 南京 211189
  • 出版日期:2014-10-25 发布日期:2017-06-19

Design and implementation of high-speed network traffic sensor for emergency response

Ya-zhou MA,Jian GONG,Wang YANG   

  1. School of Computer Science and Engineering,Southeast University,Nanjing 211189,China
  • Online:2014-10-25 Published:2017-06-19

摘要:

摘 要:网络安全应急响应在网络分析和追踪时需要应急采集,即捕获特定IP、端口、协议的原始分组。基于高速网络分组捕获工具PF_RING DNA,利用多核多线程并发采集与规则匹配的网络分组,并分配共享缓冲区提高分组的磁盘存储性能,同时通过对采集规则设置不同的状态,实现动态添加采集规则和人为干预采集过程。实验结果表明,在双万兆网卡的环境下,应急采集系统可以捕获并处理19.98 bit/s(3.5 Mpacket/s)的网络流量,最大应急采集速率为1 297 Mbit/s(204.9 kpacket/s)。

关键词: 应急响应, PF_RINGDNA, 分组采集, 动态规则

Abstract:

In the network analysis and tracking,network security emergency response needs a emsrgency sensor that captures saw packets of specific IP,port,protocol.Base on the high-speed packet capture tool PF_RING DNA,it uses mutil-thread to capture network packets that match sensor rules,and allocates the shared buffer to improve the performance of the disk storage of packets,at the same time through setting different states for the packet sensor rule,impliments adding sensor rules and human intervention dynamically.The experimental results show that in the dual 10 Gigabit NICs environment,emergency sensor can capture and handle network traffic of 19.98 Gbit/s(3.5 Mpacket/s),and the maximum rate of emergency sensor is 1 297 Mbit/s(204.9 kpacket/s).

Key words: emergency response, PF_RING DNA, packet capture, dynamic rule

No Suggested Reading articles found!