Efficiency Analysis of Network Traffic Processing by the Netfilter Subsystem in Linux Depending on Available CPU Processing Power
摘要
In this article the basic principles of operation of the netfilter subsystem in Linux, for comprehensive processing and filtering of network packets, are considered. The authors created a test bench for the correct assessment of the performance of filtering network traffic from the clock frequency of the central processor, on which the results of measuring the performance of traffic for the transmission of TCP and UDP were obtained. Additional studies were conducted with and without network traffic filtering. Based on the data obtained, graphs of the corresponding dependencies were constructed, the analysis of which showed that optimal filtering performance for a particular system can be achieved at a lower CPU clock frequency and further increase in the latter will lead to disproportionate performance growth. Accordingly, the optimal clock frequency range can be characterized by a close-to-linear increase in performance at a fixed frequency change step—this condition is not observed at higher clock frequencies of the studied CPU. This opens up great opportunities for considering the energy efficiency of systems using the netfilter subsystem in Linux for traffic processing. Recommendations have been developed that open up opportunities for further improvement of the scalability of network solutions based on Linux and optimization of the efficiency of such systems.