18.08.2016

CAPTURE BACKENDS

NameCapture speedInstallationCPU loadPlatformsCostAccuracy of attack detectionSpeed of attack detection
netmapUp to wire speed (10GE, 14 MPPS)Need kernel module and patched NIC drivers (igb, ixgbe, i40 supported). For FreeBSD could need kernel rebuildNormalLinux, FreeBSDBSDVery accurateVery fast
PF_RINGUp to 2-3 MPPS, 2-3 GENeed kernel module installVery bigLinux onlyGPLv2Enough accurateVery fast
PF_RING ZCUp to wire speed (10GE, 14 MPPS)Need kernel module + patched drivers (provided in package)NormalLinux onlyCommercial ~200 euroVery accurateVery fast
pcapVery slow, 10-100 mbpsSimpleHugeFreeBSD, LinuxGPLNot so accurateVery fast
sFLOWUp to 40-100GEVery simpleSmallLinux, FreeBSD, MacOSFreeAccurate but depends on sampling rate.Very fast
NetFlowUp to 40-100GEVery simpleSmall for FastNetMon but could be huge for network equpment if implemented in software wayLinux, FreeBSD, MacOSFree but could require additional licenses or hardware from network equipment vendorNot so accurateSo slow, up to multiple minutes depends on flow timeout configuration on routers
AF_PACKETUp to 2 MPPS/5-10GEVery simpleNormal-hugeLinux (since 3.6 kernel)GPLv2Very accurateVery fast