PF_RING
PF_RING is a new type of network socket that dramatically improves the packet capture speed.
similar
-
-
PF_RING ZC (Zero Copy) ntop.org
PF_RING ZC (Zero Copy) is a flexible packet processing framework that allows you to achieve 1/10 Gbit line rate packet processing (both RX and TX) at any packet size. It implements zero copy operations including patterns for inter-process and inter-VM (KVM) communications.
-
PFQ github.com
PFQ is a functional networking framework designed for the Linux operating system that allows efficient packets capture/transmission (10G and beyond), in-kernel functional processing and packets steering across sockets/end-points.
-
PacketFu github.com
-
The BSD Packet Filter: A New Architecture for User-level Packet Capture tcpdump.org
The original paper about (classic) BPF.
-
OpenFPC github.com
OpenFPC is a set of scripts that combine to provide a lightweight full-packet network traffic recorder & buffering tool. Its design goal is to allow non-expert users to deploy a distributed network traffic recorder on COTS hardware while integrating into existing alert and log…
Security › Network > Fast Packet Processing: “PF_RING is a new type of network socket that dramatically improves the packet capture speed.”
PCAPTools › Traffic Capture: “PF_RING is a new type of network socket that dramatically improves the packet capture speed. Available for Linux kernels 2.6.32 and newer. No need to patch the kernel. PF_RING-aware drivers for increased packet capture acceleration.”