PF_RING seems to be used for the newest version of ntop for faster packet capture and analysis. Is that what you are trying to accomplish?
Yes. this is the reason why we turn back on PF_RING to patch the kernel. Generally, the libpcap can not meet our need to capture the network packets.
Or did I just get a bad google?
Sorry, what do you mean?