I tried to run Snort on Qualcomm SA8155P Platform in Android 11/Linux with nfqueue mode as an IDPS.
And I configured two network interface (One Ethernet interface and one WLAN interface.) with common rules. (e.g. flood attack from any to any.)
When I run an Android application (such as YouTube) to cache some video in 720P or 1080P or send some traffic in about 2.4M/s, cpu usage runs up from 0.6% to 97%.
Add a custom configuration for a specific traffic might be difficult cause our configuration on network interface.
Shall someone give me some other idea for this? Thanks so much~