Re: Continuous packet capture

Brad Lhotsky <[email protected]>
Newsgroups gmane.comp.lang.perl.poe
Message-ID <[email protected]>
I'm not sure that POE::Component::Pcap works like the 
POE::Component::Server::TCP.  It appears to be implemented as a separate 
POE::Session and uses select() with an internal file descriptor to poll 
the device for new packets and fire the events specified by the dispath 
argument.

Jonathan S. Polacheck wrote:
> Nosing around in the mailing list archive I find;
> 
> 
> "Re: Prioritizing Event Loops
> 
> Martijn van Beers
> Fri, 18 Jan 2008 11:37:22 -0800
> <snip>
> In POE, all your external data, whether from a socket or a file, or
> something else entirely, enters your app through a POE::Wheel (you might
> not be aware of having one, since it is mostly hidden inside
> POE::Component::Server::TCP). How the wheel gets the data is supposed to be
> abstracted away.
> </snip>"
> 
> So POE::Component::Pcap is a wheel?
> 
> Jon
> 
> __________________
> 
> Brad,
> 
> Great stuff.  Thanks.  I'm going on the assumption that $inst->[1] (line
> 94) is the raw packet, headers and all.  I plan to test by pointing pcap at
> a capture file and comparing output to input.  My next plan is to add a sql
> insert of $hexpacket at line 108.  My goal is to keep up with an incoming
> data stream of 20-30 k-bytes a second.  After the hex data is safely stored
> in the database I can go back and insert whatever fields (layer 3-4, packet
> length, etc) I want.  Then do a gui to extract traces and do other analysis
> from the stored data.   Here is my code;
> 
>   1  use strict;
>   2  use warnings;
>   3
>   4  use Data::Dumper;
>   5  use Carp;
>   6
>   7  #
>   8  # POE Environment
>   9  # use POE qw(
>  10  #      Component::Pcap
>  11  #      Component::Daemon
>  12  # );
>  13
>  14  use POE qw(
>  15   Component::Pcap
>  16  );
>  17
>  18  #
>  19  # PCAP Options
>  20  my %pcap_opts = (
>  21   dev         => 'eth0',
>  22   snaplen           => 1514,
>  23   promisc           => 1,
>  24   timeout           => 100,
>  25  );
>  26
>  27  #------------------------------------------------------------------------#
>  28  # POE Environment Setup
>  29  #------------------------------------------------------------------------#
>  30  #POE::Component::Daemon->spawn( detach => 1, babysit => 600, max_children => 5 );
>  31
>  32  POE::Session->create(
>  33   inline_states     => {
>  34         _start                  => \&start_processor,
>  35         _stop             => \&stop_processor,
>  36         handle_packet           => \&handle_packet,
>  37   },
>  38  );
>  39
>  40  $_[HEAP]->{i} = 0;
>  41
>  42  #------------------------------------------------------------------------#
>  43  # Run the POE Sessions
>  44  #------------------------------------------------------------------------#
>  45  POE::Kernel->run;
>  46
>  47  #------------------------------------------------------------------------#
>  48  exit 0;
>  49  #------------------------------------------------------------------------#
>  50
>  51  #------------------------------------------------------------------------#
>  52  # Start the Processor
>  53  sub start_processor {
>  54   my ($kernel, $heap) = @_[KERNEL, HEAP];
>  55
>  56   $kernel->alias_set('processor');
>  57
>  58   #
>  59   # Start Packet Capturing
>  60   POE::Component::Pcap->spawn(
>  61         Alias       => 'pcap',
>  62         Device            => $pcap_opts{dev},
>  63         Dispatch    => 'handle_packet',
>  64         Session           => 'processor',
>  65   );
>  66   $kernel->post( pcap => open_live => @pcap_opts{qw(dev snaplen promisc timeout)} );
>  67
>  68   $kernel->post( pcap => 'run' );
>  69  }
>  70  #------------------------------------------------------------------------#
>  71
>  72  #------------------------------------------------------------------------#
>  73  # stop the processor
>  74  sub stop_processor {
>  75   my ($kernel,$heap) = @_[KERNEL,HEAP];
>  76
>  77   #
>  78   # Stop pcap
>  79   $kernel->post( 'pcap' => 'shutdown' );
>  80  }
>  81  #------------------------------------------------------------------------#
>  82
>  83  #------------------------------------------------------------------------#
>  84  sub handle_packet {
>  85   my $offset = 0;
>  86   my $linechars = 0;
>  87   my $hexpacket;
>  88
>  89   $_[HEAP]->{i}++;
>  90   print "sub handle_packet called $_[HEAP]->{i} times\n";
>  91   my ($kernel,$heap,$packets) = @_[KERNEL,HEAP,ARG0];
>  92
>  93   foreach my $inst ( @{ $packets } )  {
>  94         foreach my $char (split(//, $inst->[1])) {
>  95               if ( $linechars == 0 ) {
>  96                     $hexpacket .= sprintf( "%04X ", $offset );
>  97               }
>  98               $linechars++;
>  99               $hexpacket .= sprintf( "%02X ", ord($char) );
> 100               if ( $linechars == 16 ) {
> 101                     $hexpacket .= "\n";
> 102                     $linechars = 0;
> 103                     $offset += 16;
> 104               }
> 105         }
> 106         $hexpacket .= "\n\n";
> 107   }
> 108   print $hexpacket;
> 109   undef($hexpacket);
> 110  }
> 111
> 112  #------------------------------------------------------------------------#
> 

-- 
Brad Lhotsky <[email protected]>
NCTS Computer Specialist  -- 410.558.8006
..  WAR IS PEACE,
     FREEDOM IS SLAVERY,
     IGNORANCE IS STRENGTH ..
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.