in Programming

Processing network captures in pcap format

I would like to build my own tool for analyzing network captures.

Most of the time my job involves to spot why a network protocol is performing slowly: using Wireshark for that task is nice, but I want something more automatic, just able to detect the issues I normally deal with, in an automatic way.

That is the reason I have decided to do some homework and analyze which libraries are available for processing pcap files.

The original pcap library in C can be found @ tcpdump.org

Information about the file format can be found @ Libpcap information

There is a port to python of the pcap library Python port of the pcap library

Also in Python, there is a tool that seems to be much more ambitious but worthy: Scapy

This is just a first sketch. Lot of job needs to be done to accomplish something useful.