Login Register






PcapPlusPlus filter_list
Author
Message
PcapPlusPlus #1
PcapPlusPlus is a multiplatform C++ network sniffing and packet parsing and crafting framework. PcapPlusPlus is meant to be lightweight, efficient and easy to use.

[Image: a49577e68a.png]

What makes PcapPlusPlus different from similar C++ wrappers for libpcap/WinPcap?
  • Designed to be lightweight and efficient
  • Support for DPDK fast packet processing engine which enables packet capturing and transmition in line rate using kernel bypass
  • Support for ntop's PF_RING packet capturing engine that dramatically improves the packet capture speed
  • Support for parsing and editing of many protocols, including L5-7 protocols like HTTP, SSL/TLS and SIP
  • Unique implementation of TCP reassembly logic which includes support of TCP retransmission, out-of-order TCP packets and missing TCP data
  • Support for Remote Capture capabilities on Windows (using RPCAP protocol supported in WinPcap)
  • Support for reading and writing PCAPNG files (a lot more more than currently supported in WinPcap/libpcap)
  • Vast object-oriented filtering mechanism that makes libpcap filters a lot more user-friendly (no need to know the exact filter string to use)
Supported Protocols
The Packet++ library currently supports parsing, editing and creation of packets of the following protocols:
  1. Ethernet
  2. SLL (Linux cooked capture)
  3. Null/Loopback
  4. Raw IP (IPv4 & IPv6)
  5. IPv4
  6. IPv6
  7. ARP
  8. VLAN
  9. VXLAN
  10. MPLS
  11. PPPoE
  12. GRE
  13. TCP
  14. UDP
  15. ICMP
  16. IGMP (IGMPv1, IGMPv2 and IGMPv3 are supported)
  17. SIP
  18. SDP
  19. DNS
  20. DHCP
  21. HTTP headers (request & response)
  22. SSL/TLS - parsing only (no editing capabilities)
  23. Generic payload

[Image: Vs4P58c.png]

Reply