摘要
分析了大规模网络环境下信息监测系统所面临的主要问题,设计并实现了大规模网络环境下高可扩展的信息监测系统(SIMS)。基于零拷贝的报文捕获机制和多线程TCP/IP协议栈是SIMS的主要技术,实验证明能够明显提高数据的捕获能力和协议还原分析能力,适合于大规模网络环境下的实时信息监测;同时采用基于PLUGIN的协议还原平台,使SIMS具有更好的可扩展性。
A scalable information monitoring system based on large-scale network(SIMS) has been designed and implemented by analyzing the performance bottleneck of traditional information monitoring system.In the SIMS,packets acquisition technology based on zero-copy method and multithreading protocol library are adopted.Experiment results indicate that the performance of the data capture and protocol analysis have been improved remarkably.In addition,SIMS has characteristic of high scalability by adopting the protocol analysis platform based on plugin.
出处
《计算机工程与应用》
CSCD
北大核心
2005年第25期152-154,232,共4页
Computer Engineering and Applications
关键词
大规模网络
信息监测
零拷贝
多线程
PLUGIN
协议还原
large-scale network,information monitoring,zero-copy,multithreading,plug-in,protocol analysis