BLOG     |     FORUM
Welcome, Guest
Username: Password: Remember me
All your questions answered real quick by Unleash Networks Engineers.
  • Page:
  • 1

TOPIC: Create a Custom Routine to Parse P2P traffic

Create a Custom Routine to Parse P2P traffic 13 years 9 months ago #307

  • ChuckFL
  • ChuckFL's Avatar
I am a law enforcement office in Florida, USA. I am attached to state and federal task forces.

I just found this software. I am looking for the ability to build/ have built a plug-in to parse Gnuetella style peer to peer traffic (ie Limewire and such).

It looks like this is a very good extensible platform for such work.

I would like to hear comments on the possibilities and feasibility.

Thanks!!

Chuck
The administrator has disabled public write access.

Re:Create a Custom Routine to Parse P2P traffic 13 years 9 months ago #308

Hi Chuck,

Yes you could build a plugin to parse the Gnutella protocol fairly easily with Unsniff. That part is straight forward.

I guess you would be interested in reconstructing actual files transferred over these networks. You could do that too with Unsniff, but it will require some coding. I can help with that part, we are lucky because most Gnutella traffic is unencrypted today.

Tools like Unsniff and Wireshark are great for pulling in traffic dumps (pcaps) of a finite size, hopefully pre filtered.

I think you want to look at our new product called Trisul Network Metering and Forensics. www.unleashnetworks.com/products/trisul.html.

In a nutshell, Trisul listens to traffic and indexes raw content and flows with fine grained traffic statistics. This enables you to retro analyze (back in time - as much as disk space allows) incidents.

Sorry for the loong reply.

You can also email me at vivek [ at ] unleashnetworks if you want to discuss a bit more about this.

Thanks,

Vivek R
Unleash Networks
Vivek R
Unleash Networks
Support : www.unleashnetworks.com/forums
The administrator has disabled public write access.
  • Page:
  • 1
Moderators: vivek [unleash]
Time to create page: 0.027 seconds