Get the App
SLTechnology News&Howtos  ›  Network Security  › 

C language analysis packet program

Shulou Source: shulou.com Published: 2022-06-01 03:02:07 09月25日 Update

# include # include / * / typedef struct value {u_int32_t sip; / * Source IP*/ unsigned long long packets; / * number of reports * / unsigned long long tcp; unsigned long long udp; unsigned long long icmp Unsigned long long other; unsigned long long bytes; / * traffic * /} value;/* * / typedef struct {value v; / * structure value*/ unsigned long long fpacket; / * incoming packets * / unsigned long long fbytes; / * incoming traffic * /} xvalue # define HASHSIZE 10000 / * hash table size * / # define HASHSIZEIN 1000 / * hash table size * / / * Custom structure * / typedef struct node {u_int32_t ip; / / ip address. The sub-structure records the following attribute unsigned long long bytes; / * bytes * / unsigned long long packets corresponding to Ip / * number of packets * / unsigned long long fbytes; / * incoming traffic * / unsigned long long fpacket; / * number of packets * / unsigned long long tcp; / * whether it is tcp protocol * / unsigned long long udp; / * whether it is udp protocol * / unsigned long long icmp / * whether it is icmp protocol * / unsigned long long other; / * other * / struct node * next; / * next node pointer * /} htnode;typedef htnode * * hashtable;unsigned long long in_bytes; / / incoming traffic unsigned long long in_packets / / number of inbound packets unsigned long long out_bytes; / / outbound traffic unsigned long long out_packets=0; / / number of outbound packets bpf_u_int32 netp,maskp; / * Network address, subnet mask * / hashtable ht,ht_out; pthread_mutex_t hash_lock; / * thread lock * / pthread_attr_t attr;sigset_t mask_sig Int hash (u_int32_t ip, int size) {return ip% size;} htnode * hashtable_search (hashtable T, int size, u_int32_t ip) {htnode * p = T [hash (ip, size)]; while (packs null & & p-> IP) pamphp-> next; return p;} int hashtable_insert (hashtable T, int size, htnode * s) {int d; htnode * p=hashtable_search (T, size, s-> ip) If (paired null) {p-> fbytes + = s-> fbytes; p-> fpacket + = s-> fpacket; p-> bytes + = s-> bytes; p-> packets + = s-> packets; p-> tcp + = s-> tcp; p-> udp + = s-> udp; p-> icmp + = s-> icmp; p > other + = s-> other; free (s) Else {d=hash (s-> ip, size); s-> next = T [d]; T [d] = s;} / / Hash table destruction void hashtable_descrty (hashtable h, int size, int in_out) {value * null; int sock,j=1; struct sockaddr_in svraddr; if ((sock = socket (AF_INET, SOCK_STREAM, 0))

< 0){ exit(1); } svraddr.sin_family = AF_INET; svraddr.sin_port = htons(4200); if(inet_pton(AF_INET, "IP地址", &svraddr.sin_addr) < 0){ exit(1); } //将IP地址由点分十进制 转为 网络字节序格式 if(connect(sock, (const struct sockaddr *)&svraddr, sizeof(svraddr)) < 0){ close(sock);return; } //启动socket,连接服务端,准备推送数据 memset(&vs[0], 0, sizeof(xvalue)); //外网ip记录的数据 if(in_out==0){ vs[0].v.other = 0; vs[0].fbytes = out_bytes; vs[0].fpacket = out_packets; //内网ip记录的数据 }else{ vs[0].v.other = 1; vs[0].fbytes = in_bytes; vs[0].fpacket = in_packets; } int i; for (i = 0; i < size; i++) { htnode *p,*t; p = h[i]; if (p ==NULL ) continue; while(p->

Next! = NULL) {vs.v.sip = p-> ip; vs[ j] .v.tcp = p-> tcp; vs.v.udp = p-> udp; vs.v.icmp = p-> icmp; vs.v.other = p-> other; vs[ j] .v.bytes = p-> bytes Vs [j] .v.packets = p-> packets; vs [j] .fbytes = p-> fbytes; vs [j] .fpacket = p-> fpacket; jacked packets; t = p-> next; free (p); pause;} vs.v.sip = p-> ip; vs [j] .v.tcp = p-> tcp Vs[ j] .v.udp = p-> udp; vs.v.icmp = p-> icmp; vs.v.other = p-> other; vs.v.bytes = p-> bytes; vs.v.packets = p-> packets; vs [j] .fbytes = p-> fbytes; vs.fpacket = p-> fpacket; jacks + Free (p); pendant null;} free (h); hull null; write (sock, vs, sizeof (xvalue) * j); / / transfer data to the server close (sock);} int insert_top (hashtable T, htnode * p, int newsize) {struct in_addr addr; htnode * t dint; int i; for (I = 0; I

< newsize; ++i) { if (T[i] != NULL){ if(p->

Bytes > T [I]-> bytes) {t = T [I]; int junii; while (jnext = NULL; T [I] = p; return 0;}} else {p-> next = NULL; T [I] = p; return 0 }} return 1;} hashtable hashtable_top (hashtable h, int size, int newsize) {hashtable topht; if ((topht = (struct node* *) calloc (newsize, sizeof (struct node*) = = NULL) exit (- 1); int i; for (I = 0; I

< size; i++) { htnode *p,*t; p = h[i]; if (p ==NULL ) continue; while(p->

Tags: Data traffic address structure process packet header network network service Ethernet size bytes Ethernet representative information memory decimal target decimal subnet Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Docker Xiaomi macOS Microsoft MySQL