Preliminary results on the Linux libpcap model identification

Michal P. Karpowicz, Piotr Arabas
  • August 2015, Institute of Electrical & Electronics Engineers (IEEE)
  • DOI: 10.1109/mmar.2015.7284025

Packet inspection dynamics in the Linux kernel

What is it about?

The article presents the results of studies in which models of the Linux system packet capture operations were identified. Performance of the kernel-level packet filters was recorded in a series of adequately designed experiments.

Why is it important?

Based on the collected data linear models of CPU workload were estimated and analyzed in time and frequency domain. Models of low orders were obtained that provide satisfactory fit to estimation data with normally distributed residuals. These models can be used in the design of CPU controllers or intrusion detection systems.


Dr Michał P. Karpowicz (Author)
Politechnika Warszawska

We propose a method which allows to identify high-resolution models of packet processing dynamics in the Linux kernel. Design of customized probes is discussed as well.

