Project

General

Profile

Actions

Feature #681

closed

Implement TPACKET_V3 support in AF_PACKET

Added by Eric Leblond almost 12 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Suricata only supports TPACKET_V2 in AF_PACKET capture. The version 3 of packet allows to have a non fixed packet size in the ring buffer. This is supposed to increase capture performance on network with small packets.

Actions #1

Updated by Victor Julien over 11 years ago

  • Assignee set to Eric Leblond

Seems the protocol is not documented and example code is missing. Might be hard to get it working.

Actions #2

Updated by Victor Julien about 11 years ago

  • Target version set to TBD
Actions #3

Updated by Victor Julien almost 11 years ago

  • Status changed from New to Assigned
  • Target version changed from TBD to 3.0RC2
Actions #4

Updated by Victor Julien about 10 years ago

  • Priority changed from Normal to Low
  • Target version changed from 3.0RC2 to TBD

Seems this API isn't all that much of an improvement?

Actions #5

Updated by Eoin Miller almost 10 years ago

We noticed quite an increase in performance (around %25) when implementing in our sniffer. It would be great is Suricata was able to support this as well.

Actions #7

Updated by Victor Julien almost 10 years ago

Eoin, since you have an implementation, are you interested in contributing it?

Actions #8

Updated by Victor Julien over 8 years ago

  • Priority changed from Low to Normal
  • Target version changed from TBD to 70
Actions #9

Updated by Victor Julien over 8 years ago

  • Status changed from Assigned to Closed
  • Target version changed from 70 to 3.1rc1
Actions

Also available in: Atom PDF