Accurate, low-overhead per process bandwidth monitoring on Linux in 40 lines of bpftrace
/proc/net/tcp6 to get a mapping from connected TCP endpoints to inodes, capturing all traffic using libpcap, parsing each packet, and finding which process owns the TCP connection of each packet. This approach comes with two disadvantages: it requires a costly copy from kernel space to user space for every single packet; it is blind to all non-TCP traffic (see issues/62 We can easily build accurate monitoring for all traffic in only 40 lines of code for bpftrace. bpftrace bpftrace is tracing tool for Linux that allows defining tracing programs that get entirely executed within the kernel. I...