⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 pcap.txt

📁 libcap是常用的linux抓包程序,属于open source项目.
💻 TXT
📖 第 1 页 / 共 5 页
字号:
       0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1      +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+      |          Cell Size            |                               |      +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+                               |      |                                                               |      |                        Fixed Size Data                        |      |                                                               |      |              /* variable length, byte-aligned */              |      |                                                               |      |                                                               |      +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+                 Figure 12: Fixed Length Block format.   The fields have the following meaning:   o  Cell size: the size of the blocks contained in the data field.   o  Fixed Size Data: data of this block.5.5 Directory Block (experimental)   If present, this block contains the following information:   o  number of indexed packets (N)   o  table with position and length of any indexed packet (N entries)   A directory block must be followed by at least N packets, otherwise   it must be considered invalid. It can be used to efficiently load   portions of the file to memory and to support operations on memory   mapped files. This block can be added by tools like network analyzers   as a consequence of file processing.5.6 Traffic Statistics and Monitoring Blocks (experimental)   One or more blocks could be defined to contain network statistics or   traffic monitoring information. They could be use to store data   collected from RMON or Netflow probes, or from other network   monitoring tools.5.7 Event/Security Block (experimental)   This block could be used to store events. Events could contain   generic information (for example network load over 50%, server   down...) or security alerts. An event could be:Degioanni & Risso       Expires August 30, 2004                [Page 25]Internet-Draft    PCAP New Generation Dump File Format        March 2004   o  skipped, if the application doesn't know how to do with it   o  processed independently by the packets. In other words, the      applications skips the packets and processes only the alerts   o  processed in relation to packets: for example, a security tool      could load only the packets of the file that are near a security      alert; a monitorg tool could skip the packets captured while the      server was down.Degioanni & Risso       Expires August 30, 2004                [Page 26]Internet-Draft    PCAP New Generation Dump File Format        March 20046. Conclusions   The file format proposed in this document should be very versatile   and satisfy a wide range of applications. In the simplest case, it   can contain a raw dump of the network data, made of a series of   Simple Packet Blocks. In the most complex case, it can be used as a   repository for heterogeneous information. In every case, the file   remains easy to parse and an application can always skip the data it   is not interested in; at the same time, different applications can   share the file, and each of them can benfit of the information   produced by the others. Two or more files can be concatenated   obtaining another valid file.Degioanni & Risso       Expires August 30, 2004                [Page 27]Internet-Draft    PCAP New Generation Dump File Format        March 20047. Most important open issues   o  Data, in the file, must be byte or word aligned? Currently, the      structure of this document is not consistent with respect to this      point.Degioanni & Risso       Expires August 30, 2004                [Page 28]Internet-Draft    PCAP New Generation Dump File Format        March 2004Intellectual Property Statement   The IETF takes no position regarding the validity or scope of any   intellectual property or other rights that might be claimed to   pertain to the implementation or use of the technology described in   this document or the extent to which any license under such rights   might or might not be available; neither does it represent that it   has made any effort to identify any such rights. Information on the   IETF's procedures with respect to rights in standards-track and   standards-related documentation can be found in BCP-11. Copies of   claims of rights made available for publication and any assurances of   licenses to be made available, or the result of an attempt made to   obtain a general license or permission for the use of such   proprietary rights by implementors or users of this specification can   be obtained from the IETF Secretariat.   The IETF invites any interested party to bring to its attention any   copyrights, patents or patent applications, or other proprietary   rights which may cover technology that may be required to practice   this standard. Please address the information to the IETF Executive   Director.Full Copyright Statement   Copyright (C) The Internet Society (2004). All Rights Reserved.   This document and translations of it may be copied and furnished to   others, and derivative works that comment on or otherwise explain it   or assist in its implementation may be prepared, copied, published   and distributed, in whole or in part, without restriction of any   kind, provided that the above copyright notice and this paragraph are   included on all such copies and derivative works. However, this   document itself may not be modified in any way, such as by removing   the copyright notice or references to the Internet Society or other   Internet organizations, except as needed for the purpose of   developing Internet standards in which case the procedures for   copyrights defined in the Internet Standards process must be   followed, or as required to translate it into languages other than   English.   The limited permissions granted above are perpetual and will not be   revoked by the Internet Society or its successors or assignees.   This document and the information contained herein is provided on an   "AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING   TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING   BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATIONDegioanni & Risso       Expires August 30, 2004                [Page 29]Internet-Draft    PCAP New Generation Dump File Format        March 2004   HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF   MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.Acknowledgment   Funding for the RFC Editor function is currently provided by the   Internet Society.Degioanni & Risso       Expires August 30, 2004                [Page 30]

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -