想法
- 打开离线文件pcap_open_offline()
pcap_t *pcap_open_offline(const char *fname, char *errbuf);
pcap_t *pcap_fopen_offline(FILE *fp, char *errbuf);
is called to open a ”savefile” for reading.
fname specifies the name of the file to open. The file has the same format as those used by tcpdump(1) and tcpslice(1). The name “-” in a synonym for stdin.
Alternatively, you may call pcap_fopen_offline() to read dumped data from an existing open stream fp. Note that on Windows, that stream should be opened in binary mode.
- pcap_loop - process packets from a live capture or savefile
typedef