Project

General

Profile

Actions

Feature #3306

closed

Support AF_XDP capture method

Added by Eric Leblond almost 5 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
medium
Difficulty:
high
Label:

Description

A new capture method has been recently introduced in Linux. Named AF_XDP, it allows to capture the traffic with a kernel bypass. This limit the cost of the capture in term of CPU cycle.


Related issues 2 (2 open0 closed)

Related to Suricata - Task #3288: Suricon 2019 brainstormAssignedVictor JulienActions
Related to Suricata - Task #4097: Suricon 2020 brainstormAssignedVictor JulienActions
Actions

Also available in: Atom PDF