如题目所述, 本文主要分享一个在C++中获取pcap文件中数据包的时间戳的小程序.
//解析.c
#include <pcap.h>
#include <net/ethernet.h>
#include <netinet/ip.h>
#include <netinet/in.h>
#include <netinet/tcp.h>
#include <arpa/inet.h>
#include <stdio.h>
#include <翻译包.h>
void packetHandler(u_char *userData, const struct pcap_pkthdr* pkthdr, const u_char* packet);
int main() {
pcap_t *descr;
char errbuf[PCAP_ERRBUF_SIZE];
// open capture file for offline processing
char 文件名[] = "/Users/zongyi/traces/caida/equinix-nyc.dirA.20180419-125909.UTC.anon.pcap";
descr = pcap_open_offline(文件名, errbuf);
if (descr == NULL) {
printf("pcap_open_offline() failed: %s\n", errbuf);
return 1;
}
// start packet processing loop, just like live capture
_整数_ 数据包数 = 10; // 如果设为0, 则会遍历文件中的所有数据包
if (pcap_loop(descr, 数据包数, packetHandler, NULL) < 0) {
printf("pcap_loop() failed\n");
return 1;
}
printf("capture