Hardware nanosecond‐precision timestamping for line‐rate packet capture

Author:

Huang Xiaoying1ORCID

Affiliation:

1. Peng Cheng Laboratory Shenzhen Guangdong China

Abstract

AbstractCybersecurity events occur frequently. When it comes to investigating security threats, it is essential to offer a 100 percent accurate and packet‐level network history, which depends on packet capture with high precision packet timestamping. Many packet capture applications are developed based on data plane development kit (DPDK)—a set of libraries and drivers for fast packet processing. However, DPDK cannot give an accurate timestamp for every packet, and it is unable to truly reflect the order in which packets arrive at the network interface card. In addition, DPDK‐based applications cannot achieve zero packet loss when the packet is small such as 64 B for beyond 10 Gigabit Ethernet. Therefore, the authors proposed a new method based on Field‐Programmable Gate Array (FPGA) to solve this problem. The authors also develop a DPDK driver for FPGA devices to make the design compatible with all DPDK‐based applications. The proposed method performs timestamping at line‐rate for 10 Gigabit Ethernet traffic at 4 ns precision and 1 ns precision for 25 Gigabit, which greatly improves the accuracy of security incident retrospective analysis. Furthermore, the design can capture full‐size packets for any protocol with zero packet loss and can be applied to 40/100 Gigabit systems as well.

Funder

National Key Research and Development Program of China

Publisher

Institution of Engineering and Technology (IET)

Reference35 articles.

1. Data-Driven Cybersecurity Incident Prediction: A Survey

2. Cisco 2018 annual cybersecurity report.https://www.cisco.com/c/dam/m/hu_hu/campaigns/security‐hub/pdf/acr‐2018.pdfAccessed 1 May 2023

3. Challenges of managing and securing the network(2019).https://www2.endace.com/cmsn‐2019Accessed 1 May 2023

4. nCap: wire-speed packet capture and transmission

5. PacketShader

Cited by 1 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Meeting Latency and Jitter Demands of Beyond 5G Networking Era: Are CNFs Up to the Challenge?;2024 IEEE 48th Annual Computers, Software, and Applications Conference (COMPSAC);2024-07-02

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3