PF_RING – High-Speed Packet Capture, Filtering And Analysis

PF_RING - High-Speed Packet Capture, Filtering And Analysis

PF_RING™ is a brand new kind of community socket that dramatically improves the packet seize velocity, and that’s characterised by the next properties:

  1. Available for Linux kernels 2.6.32 and newer.
  2. No must patch the kernel: simply load the kernel module.
  3. 10 Gbit Hardware Packet Filtering utilizing commodity community adapters
  4. User-space ZC (new technology DNA, Direct NIC Access) drivers for excessive packet seize/transmission velocity because the NIC NPU (Network Process Unit) is pushing/getting packets to/from userland with none kernel intervention. Using the 10Gbit ZC driver you’ll be able to ship/obtained at wire-velocity at any packet sizes.
  5. PF_RING ZC library for distributing packets in zero-copy throughout threads, purposes, Virtual Machines.
  6. Device driver unbiased.
  7. Support of Accolade, Exablaze, Endace, Fiberblaze, Inveatech, Mellanox, Myricom/CSPI, Napatech, Netcope and Intel (ZC) community adapters.
  8. Kernel-based packet seize and sampling.
  9. Libpcap assist (see under) for seamless integration with present pcap-primarily based purposes.
  10. Ability to specify hundred of header filters along with BPF.
  11. Content inspection, in order that solely packets matching the payload filter are handed.
  12. PF_RING™ plugins for superior packet parsing and content material filtering.

If you wish to learn about PF_RING™ internals or for the User’s Manual go to the Documentation part.


Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.