Method for realizing data packet catching based on sharing internal memory

A shared memory and data packet technology, applied in the field of data packet capture, can solve the problems of high price and lack of flexibility of the traffic monitoring and analysis system, and achieve the effect of eliminating memory copy overhead, saving CPU resources, and reducing the number of system calls

CN1925465AInactive Publication Date: 2007-03-07INST OF COMPUTING TECH CHINESE ACAD OF SCI
0 Cites 33 Cited by

Patent Information

Authority / Receiving Office
CN · China
Current Assignee / Owner
Publication Date
2007-03-07
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

This invention discloses one data package capture method based on sharing memory, which comprises the following steps: net card loading and initiating drive program; establishing character device; setting monitor terminal card as mixture mode; receiving data package to judge receive terminal; judging data package into data information area; if not discarding data package; initiating management information unit; operating flow monitor analysis program; opening character device to get needle; extracting data package to introduce number label section then executing next step; executing monitor analysis program to change total index data to visit label section as processed data package.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The present invention relates to the technical fields of computer network flow monitoring and analysis, network card driver, and operating system memory management, and in particular to a data packet capture method based on a common hardware platform and open-source software based on shared memory in kernel space and user space. Background technique

[0002] Traffic index is one of the most important indexes in the process of network operation and maintenance. It is the basis of network planning and design, protocol design, service deployment, traffic engineering implementation, attack detection and fault diagnosis. Network performance information, network service status, and attacks or weaknesses in the network can be obtained through monitoring and analyzing network traffic. Traffic monitoring and analysis technologies are widely used in firewalls, intrusion detection (such as snort, Bro, etc.) and protocol decoding and traffic monitoring (such as et...

Examples

Embodiment Construction

[0042] The method of the present invention will be further described below in conjunction with the accompanying drawings and specific embodiments.

[0043] In one embodiment, the packet capture method based on shared memory of the present invention is implemented on Baode 2U blade server, the main frequency of the CPU of the server is double XEON 3.2G, the main frequency of the PCI-X slot is 133MHz, and the memory It is 1GB, and the network card model is Intel(R) PRO / 1000MT Server Adapter. The server's operating system is Fedora Core 3, the kernel version number is linux-2.6.9SMP; the network card driver version is Intel e1000-6.3.9.

[0044] On above-mentioned hardware platform, as shown in Figure 4, method of the present invention comprises the following steps:

[0045] Step 10, the network card starts to work, loads the modified network card driver, and initializes the driver. In the initialization process, the network card driver applies to the operating system for a pie...