Skip to content

Latest commit

 

History

71 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Packet Analyzer

A lightweight network packet analyzer written in C using libpcap.

The goal of this project is to understand how network protocols work at the byte level by capturing raw packets and manually dissecting their protocol headers instead of relying on high-level packet-parsing libraries.

Article : https://dikshantadi.github.io/packet_sniffer/

Current Architecture

                         Captured Packet
                                │
                                ▼
                           Ethernet
                                │
                            EtherType
                                │
                  ┌─────────────┼─────────────┐
                  ▼             ▼             ▼
                IPv4           IPv6           ARP
                  │             │
               Protocol     Next Header
                  │             │
          ┌───────┼───────┐ ┌──┼──────────────┐
          ▼       ▼       ▼ ▼  ▼              ▼
         TCP     UDP    ICMP TCP UDP        ICMPv6
          │       │             │              │
          │       │             │              ▼
          │       │             │             NDP
          └───────┴─────────────┴────────────────
                                │
                                ▼
                          Flow Tracking
                                │
                                ▼
                       Statistical Analysis
                                │
                                ▼
                           CSV Export

To try it out

Build

Make sure libpcap is installed

sudo apt install libpcap-dev

Download the source code from the GitHub Releases page, extract it, and build the analyzer with:

make

which produces

packet-analyzer

Run

Then run the analyzer with privilege:

sudo ./packet-analyzer

Precompiled Binary

A precompiled Linux x86_64 binary is available in the GitHub Releases page.

The binary requires the runtime dependencies used by the project, including libpcap.

Currently Parsed

Ethernet

  • Destination MAC address
  • Source MAC address
  • EtherType

ARP

  • Hardware Type
  • Protocol Type
  • Hardware Length
  • Protocol Length
  • Operation
  • Senders MAC
  • Senders IP
  • Target MAC
  • Target IP

IPv4

  • Version
  • Internet Header Length (IHL)
  • Time To Live (TTL)
  • Total Length
  • Identification
  • Flags
    • Dont Fragment
    • More Fragment
  • Fragment Offset
  • Protocol
  • Header Checksum
  • Source IP address
  • Destination IP address

IPv6

  • Version
  • Traffic Class
  • Flow Label
  • Payload Length
  • Next Header
  • Hop Limit
  • Source IP address
  • Destination IP address
  • IPv6 Extention Headers

TCP

  • Source Port
  • Destination Port
  • Sequence Number
  • Acknowledgment Number
  • Data Offset
  • TCP Header Length
  • TCP Flags
    • URG
    • ACK
    • PSH
    • RST
    • SYN
    • FIN
  • Window Size
  • Checksum
  • Urgent Pointer

TCP Options

  • End of Option List (EOL)
  • No-Operation (NOP)
  • Maximum Segment Size (MSS)
  • Window Scale
  • SACK Permitted
  • Selective Acknowledgment (SACK)
  • Timestamps

UDP

  • Source Port
  • Destination Port
  • Checksum
  • Length

ICMPv4

  • Type
  • Code
  • Checksum
  • Echo Request
  • Echo Reply
  • Identifier
  • Sequence Number

ICMPv6

  • Type
  • Code
  • Checksum
  • Echo Request
  • Echo Reply
  • Identifier
  • Sequence Number
  • NDP

Packet Filtering

  • Berkeley Packet Filter (BPF)

Flow Statistics

The analyzer groups TCP and UDP packets into bidirectional flows and collects statistics for each flow.

  • Total packets
  • Total bytes
  • Packets from endpoint A → B
  • Packets from endpoint B → A
  • Bytes from endpoint A → B
  • Bytes from endpoint B → A
  • Flow duration
  • Packet rate
  • Byte rate
  • Inter-arrival time
  • Average inter-arrival time
  • Minimum inter-arrival time
  • Maximum inter-arrival time
  • Inter-arrival time standard deviation
  • Minimum packet size
  • Maximum packet size
  • Average packet size

These measurements make it possible to examine traffic behavior beyond simply identifying protocols.

CSV Export

Flow statistics can be exported to CSV for further analysis.

The exported data includes:

  • Flow endpoints
  • Protocol
  • Packet and byte counts
  • Directional traffic statistics
  • Flow duration
  • Packet rate
  • Byte rate
  • Inter-arrival time statistics
  • Packet-size statistics

The CSV output can later be used for statistical analysis, visualization, or networking experiments.

Why Am I Building This?

This project is primarily a Computer Networks learning project.

The goal is to understand how network protocols are represented at the byte level and how packets move through different protocol layers.

Instead of relying on a high-level packet-parsing library, the analyzer manually processes protocol headers and follows the protocol hierarchy from Ethernet through IPv4/IPv6 and into transport and control protocols.

The project also provides a foundation for carrying out network traffic measurements and experiments.

Future Work

  • Physical and Wireless Decoder (Learning this now)
  • Application-layer protocol parsing

(Further protocol and wireless features are left as potential future extensions rather than part of the current implementation)

Technologies

  • C
  • libpcap
  • Linux
  • Make
  • Git
  • Valgrind

About

A C packet analyzer built to understand network protocols from raw bytes, with detailed documentation of how packets work.

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages