Ethereal-users: Re: [Ethereal-users] tcpdump vs ethereal

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Wed, 19 Nov 2003 14:34:11 -0800

On Nov 19, 2003, at 2:27 PM, Guy Harris wrote:

It might involve a binary kernel module, or the memory-mapped turbopacket stuff, combined with writing either to a raw RAID array or to a thin file system (or maybe one of the Linux file systems is fast enough).

One of their competitors (mentioned in some article about NAI's InfiniStream):

	http://www.sandstorm.net/products/netintercept/

runs atop a modified FreeBSD 4.8 kernel plus "minimal set of UNIX utilities":

	http://www.sandstorm.net/products/netintercept/specs

and saves "in tcpdump-format files":

	http://www.sandstorm.net/products/netintercept/technical