Session reconstruction from Pcap Files?
Hello,
I'm trying to perform some analysis on pcap files. I've written a script using Perl's Net::TcpDumpLog which allows me to parse each individual packet and extract header information as well as the payload. For example, here's what I'm currently printing out: Code:
IP_SRC,IP DST, IP_LENGTH, IP_TOS, IP_TTL, IP_Offset, TCP_ACK, TCP_flags, TCP_Winsize, TCP_Chksum, TCP_URG I want to be in a position where I have, say, a flow object which consists of all the packet objects which make up the flow. Ultimately I want to create output containing stats on each flow, one flow per line. For example: Code:
Flow_num, IP_Src, IP_Dst, TCP_SrcPort, TCP_DstPort, Flow_Duration, Packet_interarrival_mean, Number_of_packets_in_flow, Avg_packet_payload_size Many thanks, Glenn [1] http://www.circlemud.org/~jelson/software/tcpflow/ [2] http://www.wireshark.org/docs/man-pages/tshark.html [3] http://search.cpan.org/~worrall/Net-Analysis-0.40/ |
Try wireshark's "follow tcp stream"
|
Quote:
|
All times are GMT -5. The time now is 08:31 PM. |