Performance Implications of Packet Filtering with Linux eBPF

Performance Implications of Packet Filtering with Linux eBPF
复制标题

使用 Linux eBPF 进行数据包过滤的性能影响

DOI:
10.1109/itc30.2018.00039
复制
发表时间:
2018
期刊:
2018 30th International Teletraffic Congress (ITC 30)
影响因子:
--
通讯作者:
G. Carle
G. Carle
中科院分区:
--
文献类型:
--
作者:
D. Scholz;Daniel Raumer;Paul Emmerich;Alexander Kurtz;Krzysztof Lesiak;G. Carle

文献摘要

被引文献

相似文献

操作系统的防火墙功能传统上由内核中的不灵活的过滤器例程或钩子提供。这些需要配置特权访问,并且不容易扩展为自定义低级操作。从Linux 3.0开始,Berkeley Packet Filter(BPF)允许在内核处理路径中进行用户编写的扩展。继任者扩展BPF(eBPF)提高了灵活性,并通过虚拟机实现,该虚拟机具有实时(JIT)编译器和内核中运行的解释器。它执行用户提供的定制eBPF程序,有效地将内核功能转移到用户空间。我们提出了两个案例研究的使用Linux eBPF。首先,我们分析eXpress数据路径(XDP)的性能。XDP使用eBPF在分配内核数据结构之前处理入口流量,这沿着性能优势。在第二个案例研究中,eBPF用于安装作用于套接字级别的特定于应用程序的包过滤配置。我们的案例研究侧重于性能方面,并讨论其优点和缺点。
Firewall capabilities of operating systems are traditionally provided by inflexible filter routines or hooks in the kernel. These require privileged access to be configured and are not easily extensible for custom low-level actions. Since Linux 3.0, the Berkeley Packet Filter (BPF) allows user-written extensions in the kernel processing path. The successor, extended BPF (eBPF), improves flexibility and is realized via a virtual machine featuring both a just-in-time (JIT) compiler and an interpreter running in the kernel. It executes custom eBPF programs supplied by the user, effectively moving kernel functionality into user space. We present two case studies on the usage of Linux eBPF. First, we analyze the performance of the eXpress Data Path (XDP). XDP uses eBPF to process ingress traffic before the allocation of kernel data structures which comes along with performance benefits. In the second case study, eBPF is used to install application-specific packet filtering configurations acting on the socket level. Our case studies focus on performance aspects and discuss benefits and drawbacks.