2 * This program is free software; you can redistribute it and/or modify
3 * it under the terms of the GNU General Public License as published by
4 * the Free Software Foundation; either version 2 of the License, or
5 * (at your option) any later version.
7 * This program is distributed in the hope that it will be useful,
8 * but WITHOUT ANY WARRANTY; without even the implied warranty of
9 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10 * GNU General Public License for more details.
12 * You should have received a copy of the GNU General Public License
13 * along with this program; if not, write to the Free Software
14 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
18 * Author : Maxim Mamontov <faust@stargazer.dp.ua>
23 #include "stg/traffcounter.h"
24 #include "stg/plugin_creator.h"
25 #include "stg/common.h"
26 #include "stg/raw_ip_packet.h"
28 //-----------------------------------------------------------------------------
29 //-----------------------------------------------------------------------------
30 //-----------------------------------------------------------------------------
33 PLUGIN_CREATOR<PCAP_CAP> pcc;
35 const size_t SNAP_LEN 1518;
38 extern "C" PLUGIN * GetPlugin();
39 //-----------------------------------------------------------------------------
40 //-----------------------------------------------------------------------------
41 //-----------------------------------------------------------------------------
44 return pcc.GetPlugin();
46 //-----------------------------------------------------------------------------
47 //-----------------------------------------------------------------------------
48 //-----------------------------------------------------------------------------
49 std::string PCAP_CAP::GetVersion() const
51 return "pcap_cap v.1.0";
53 //-----------------------------------------------------------------------------
61 logger(GetPluginLogger(GetStgLogger(), "cap_pcap"))
64 //-----------------------------------------------------------------------------
70 DEV_MAP::const_iterator it(devices.begin());
71 while (it != devices.end())
75 char errbuf[PCAP_ERRBUF_SIZE];
77 /* get network number and mask associated with capture device */
78 if (pcap_lookupnet(it->device.c_str(), &net, &mask, errbuf) == -1)
80 errorStr = "Couldn't get netmask for device " + it->device + ": " + errbuf;
82 printfd(__FILE__, "%s\n", errorStr.c_str());
86 /* open capture device */
87 it->handle = pcap_open_live(dev, SNAP_LEN, 1, 1000, errbuf);
88 if (it->handle == NULL)
90 errorStr = "Couldn't open device " + it->device + ": " + errbuf;
92 printfd(__FILE__, "%s\n", errorStr.c_str());
96 if (pcap_setnonblock(it->handle, true, errbuf) == -1)
98 errorStr = "Couldn't put device " + it->device + " into non-blocking mode: " + errbuf;
100 printfd(__FILE__, "%s\n", errorStr.c_str());
104 /* make sure we're capturing on an Ethernet device [2] */
105 if (pcap_datalink(it->handle) != DLT_EN10MB)
107 errorStr = it->device + " is not an Ethernet";
109 printfd(__FILE__, "%s\n", errorStr.c_str());
113 /* compile the filter expression */
114 if (pcap_compile(it->handle, &it->filter, it->filterExpression.c_str(), 0, net) == -1)
116 errorStr = "Couldn't parse filter " + it->filterExpression + ": " + pcap_geterr(it->handle);
118 printfd(__FILE__, "%s\n", errorStr.c_str());
122 /* apply the compiled filter */
123 if (pcap_setfilter(it->handle, &it->filter) == -1)
125 errorStr = "Couldn't install filter " + it->filterExpression + ": " + pcap_geterr(it->handle);
127 printfd(__FILE__, "%s\n", errorStr.c_str());
131 it->fd = pcap_get_selectable_fd(it->handle);
135 errorStr = "Couldn't get a file descriptor for " + it->device + ": " + pcap_geterr(it->handle);
137 printfd(__FILE__, "%s\n", errorStr.c_str());
145 if (pthread_create(&thread, NULL, Run, this))
147 errorStr = "Cannot create thread.";
148 logger("Cannot create thread.");
149 printfd(__FILE__, "Cannot create thread\n");
155 //-----------------------------------------------------------------------------
163 //5 seconds to thread stops itself
164 for (int i = 0; i < 25 && isRunning; i++)
166 struct timespec ts = {0, 200000000};
167 nanosleep(&ts, NULL);
169 //after 5 seconds waiting thread still running. now killing it
172 if (pthread_kill(thread, SIGUSR1))
174 errorStr = "Cannot kill thread.";
175 logger("Cannot send signal to thread.");
178 for (int i = 0; i < 25 && isRunning; ++i)
180 struct timespec ts = {0, 200000000};
181 nanosleep(&ts, NULL);
185 errorStr = "PCAP_CAP not stopped.";
186 logger("Cannot stop thread.");
187 printfd(__FILE__, "Cannot stop thread\n");
192 pthread_join(thread, NULL);
198 //-----------------------------------------------------------------------------
199 void * PCAP_CAP::Run(void * d)
202 sigfillset(&signalSet);
203 pthread_sigmask(SIG_BLOCK, &signalSet, NULL);
205 PCAP_CAP * dc = static_cast<PCAP_CAP *>(d);
206 dc->isRunning = true;
216 char ethip[sizeof(ETH_IP)];
218 memset(ðip, 0, sizeof(ETH_IP));
220 ETH_IP * ethIP = static_cast<ETH_IP *>(static_cast<void *>(ðip));
221 ethIP->rp.dataLen = -1;
228 if (ethIP->ethHdr[7] != 0x8)
231 dc->traffCnt->Process(ethIP->rp);
234 dc->isRunning = false;