With the number of users on the Internet, IPv6gradually replace IPv4, IPv6network is increasing rapidly. Network users urgently need a new type of IPv6network business recognition and detection system, to ensure the security of the network, helping operators to improve service quality.This paper describes the four network data flow detection technologies:packet filtering detection, deep packet inspection (DPI), the depth of flow detection (DFI) and the state detection and comprehensive comparison and analysis of their strengths and weaknesses and the range of applications in the Internet. The system functions can be divided into three parts:data plane, identify the plane and management plane.This paper analyzes the important role of the IP fragment reassembly in the IPv6network detection system, fragment reassembly algorithm in the Linux network protocol is how to implement, and optimize the flow of business characteristics of the network traffic detection system.This paper analyzes the Linux network driver device, the detection system in dealing with the difficulty of network user behavior, and operate on multi-core processors optimized network drive.The main work of this paper is sent for three main modules of the data plane (packet capture module, the fragment reassembly modules and the flow of conversation maintenance module) study design.This paper analyzes the the IPv6session flow characteristics, and compared with IPv4, the proposed detection scheme based on IPv6five yuan group session flow, the session flow index function achieved by the look-up table of the network processor MPC8572E the session flow statistics function realized by the linked list, and through my private network where the police test to verify the functionality of the detection system. |