Het bedrijf Cloudflare open source project , which develops a packet analysis tool similar to tcpdump, built on the subsystem (eXpress Data Path). The project's code is written in Go and under a BSD license. The project also a library for binding eBPF traffic handlers from applications written in Go.
The xdpcap utility is compatible with tcpdump/libpcap filtering expressions and allows processing significantly larger volumes of traffic on the same hardware. Xdpcap can also be used for debugging in situations where standard tcpdump is not applicable, such as when filtering systems, DoS protection, and load balancing that use the Linux kernel XDP subsystem are employed, handling packets prior to their processing by the Linux kernel's network stack (tcpdump does not see packets dropped by the XDP handler).
High performance is achieved through the application of the eBPF and XDP subsystems. eBPF is a bytecode interpreter built into the Linux kernel that allows the creation of high-performance handlers for incoming/outgoing packets, making decisions on their redirection or dropping. Using a JIT compiler, eBPF bytecode is compiled on the fly into machine instructions and executed with the performance of native code. The XDP (eXpress Data Path) subsystem complements eBPF by enabling BPF programs to run at the network driver level, with direct access to the DMA buffer of packets and operating at the stage before the skbuff buffer is allocated by the network stack.
Like tcpdump, the xdpcap utility first translates high-level traffic filtering rules into classic BPF (cBPF) representation using the standard libpcap library, then transforms them into eBPF subroutine form using the , which utilizes LLVM/Clang technology. The output traffic information is saved in the standard pcap format, allowing the traffic dump prepared by xdpcap to be used later for analysis in tcpdump and other existing traffic analyzers. For example, to capture DNS traffic information instead of the command 'tcpdump ip and udp port 53', you can run 'xdpcap /path/to/hook capture.pcap ‘ip and udp port 53’', after which you can use the capture.pcap file, for instance, with the command 'tcpdump -r' or in Wireshark.
Bron: opennet.ru
