This invention discloses a traffic acquisition method and
system based on eBPF, belonging to the field of digital
information transmission technology. The method includes: filtering first
metadata based on the mapping relationship between indicators, network identifiers, and target locations; obtaining second
metadata along with its network identifier and target location; generating tunnel
metadata; and sending the tunnel metadata to a VXLAN
virtual device. The first metadata is filtered and marked using a mapping table; the identification and redirection of the first metadata are completed in kernel mode, avoiding resource overhead caused by user-mode transfer and
copying; only the filtered traffic is mirrored, avoiding bandwidth pressure on the cloud
virtual network caused by full mirroring; packet encapsulation is uniformly processed by the kernel-mode VXLAN
virtual device, reducing the complexity of header
processing and the risk of failure; the mapping table updates changes to the objects of the first node, reducing manual maintenance; and meeting the needs of
traffic analysis, auditing, and security detection.