A lightweight network packet analyzer written in C using libpcap.
The goal of this project is to understand how network protocols work at the byte level by capturing raw packets and manually dissecting their protocol headers instead of relying on high-level packet-parsing libraries.
Article : https://dikshantadi.github.io/packet_sniffer/
Captured Packet
│
▼
Ethernet
│
EtherType
│
┌─────────────┼─────────────┐
▼ ▼ ▼
IPv4 IPv6 ARP
│ │
Protocol Next Header
│ │
┌───────┼───────┐ ┌──┼──────────────┐
▼ ▼ ▼ ▼ ▼ ▼
TCP UDP ICMP TCP UDP ICMPv6
│ │ │ │
│ │ │ ▼
│ │ │ NDP
└───────┴─────────────┴────────────────
│
▼
Flow Tracking
│
▼
Statistical Analysis
│
▼
CSV Export
Make sure libpcap is installed
sudo apt install libpcap-dev
Download the source code from the GitHub Releases page, extract it, and build the analyzer with:
make
which produces
packet-analyzer
Then run the analyzer with privilege:
sudo ./packet-analyzer
A precompiled Linux x86_64 binary is available in the GitHub Releases page.
The binary requires the runtime dependencies used by the project, including libpcap.
- Destination MAC address
- Source MAC address
- EtherType
- Hardware Type
- Protocol Type
- Hardware Length
- Protocol Length
- Operation
- Senders MAC
- Senders IP
- Target MAC
- Target IP
- Version
- Internet Header Length (IHL)
- Time To Live (TTL)
- Total Length
- Identification
- Flags
- Dont Fragment
- More Fragment
- Fragment Offset
- Protocol
- Header Checksum
- Source IP address
- Destination IP address
- Version
- Traffic Class
- Flow Label
- Payload Length
- Next Header
- Hop Limit
- Source IP address
- Destination IP address
- IPv6 Extention Headers
- Source Port
- Destination Port
- Sequence Number
- Acknowledgment Number
- Data Offset
- TCP Header Length
- TCP Flags
- URG
- ACK
- PSH
- RST
- SYN
- FIN
- Window Size
- Checksum
- Urgent Pointer
- End of Option List (EOL)
- No-Operation (NOP)
- Maximum Segment Size (MSS)
- Window Scale
- SACK Permitted
- Selective Acknowledgment (SACK)
- Timestamps
- Source Port
- Destination Port
- Checksum
- Length
- Type
- Code
- Checksum
- Echo Request
- Echo Reply
- Identifier
- Sequence Number
- Type
- Code
- Checksum
- Echo Request
- Echo Reply
- Identifier
- Sequence Number
- NDP
- Berkeley Packet Filter (BPF)
The analyzer groups TCP and UDP packets into bidirectional flows and collects statistics for each flow.
- Total packets
- Total bytes
- Packets from endpoint A → B
- Packets from endpoint B → A
- Bytes from endpoint A → B
- Bytes from endpoint B → A
- Flow duration
- Packet rate
- Byte rate
- Inter-arrival time
- Average inter-arrival time
- Minimum inter-arrival time
- Maximum inter-arrival time
- Inter-arrival time standard deviation
- Minimum packet size
- Maximum packet size
- Average packet size
These measurements make it possible to examine traffic behavior beyond simply identifying protocols.
Flow statistics can be exported to CSV for further analysis.
The exported data includes:
- Flow endpoints
- Protocol
- Packet and byte counts
- Directional traffic statistics
- Flow duration
- Packet rate
- Byte rate
- Inter-arrival time statistics
- Packet-size statistics
The CSV output can later be used for statistical analysis, visualization, or networking experiments.
This project is primarily a Computer Networks learning project.
The goal is to understand how network protocols are represented at the byte level and how packets move through different protocol layers.
Instead of relying on a high-level packet-parsing library, the analyzer manually processes protocol headers and follows the protocol hierarchy from Ethernet through IPv4/IPv6 and into transport and control protocols.
The project also provides a foundation for carrying out network traffic measurements and experiments.
- Physical and Wireless Decoder (Learning this now)
- Application-layer protocol parsing
(Further protocol and wireless features are left as potential future extensions rather than part of the current implementation)
- C
- libpcap
- Linux
- Make
- Git
- Valgrind