Project

General

Profile

Actions

Feature #4820

open

Wireshark dissector: follow TCP stream

Added by Junxiao Shi almost 6 years ago. Updated almost 6 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Start date:
Due date:
% Done:

0%

Estimated time:
6.00 h

Description

Currently, ndn.lua interprets each TCP segment individually. As a result, NDN packets crossing TCP segment boundary are lost, and subsequent TCP segment could be decoded incorrectly.
This issue is to register the Wireshark dissector on top of Wireshark's TCP stream reconstruction feature, so that TCP segments are joined together before decoding as NDN protocol.
Packet boundary guess would be necessary only when the packet capture does not include the start of a TCP stream.


Files

20190117.pcap (610 KB) 20190117.pcap test case from ONL Junxiao Shi, 01/28/2019 10:25 AM
Actions #1

Updated by Junxiao Shi almost 6 years ago

John DeHart has provided a test case captured on ONL.
Frame 1267-1271 are decoded incorrectly due to missing TCP following feature, as explained in this message.

Actions

Also available in: Atom PDF