检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]上海大学通信与信息工程学院特种光纤与光接入网重点实验室,上海200444
出 处:《工业控制计算机》2022年第9期93-95,118,共4页Industrial Control Computer
摘 要:网络记录器为网络安全分析与检测提供了有效的依据,针对传统方法实现的网络记录器存在较大的性能瓶颈,设计并实现了基于MPBMS-DPDK的高速网络记录器。该系统基于DPDK处理框架,优化了高速数据报文捕获性能,创新地提出了MPBMS架构在NVME阵列上实现线速数据包存储。搭建了实验系统,实验结果和tcpdump、n2disk等传统网络记录器的性能进行对比,在10 Gbps发包速率下,对于包长为64 B的小包,该系统存储速率大约是n2disk方法的2倍,tcpdump方法的4倍。由于接收和存储的瓶颈,tcpdump方法丢包率为86%,n2disk方法丢包率为38.8%,而该系统丢包率仅为0.7%。因此该系统不管是在数据包存储速率还是数据包捕获性能上都占较大优势,能够满足记录当前网络安全问题的需求。The network recorder provides an effective basis for network security analysis and detection.In view of the large performance bottleneck of the network recorder implemented by the traditional method,this paper designs and implements a high-speed network recorder based on MPBMS-DPDK. Based on the DPDK processing framework,the system optimizes the capture performance of high-speed data packets,and innovatively proposes the MPBMS architecture to realize wire-speed data packet storage on NVME arrays.The experimental system is built and compared with the performance of traditional network recorders such as tcpdump and n2disk.The experimental results show that under the 10Gbps packet sending rate,for small packets with a packet length of 64 B,the storage rate of the system is about 2 times that of the n2disk and 4 times that of the tcpdump,due to the bottleneck of reception and storage,the packet loss rate of the tcpdump method is 86%, the packet loss rate of n2disk method is 38.8%,while the packet loss rate of this system is only 0.7%.Therefore,the system has a great advantage in both data packet storage rate and data packet capture performance,and can meet the needs of recording current network security problems.
关 键 词:DPDK 网络记录器 TCPDUMP n2disk
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.38