Ethereal-dev: Re: [ethereal-dev] Expert mode

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Jochen Friedrich <jochen@xxxxxxxx>
Date: Mon, 17 Jul 2000 17:19:47 +0200 (CEST)
Hi Richard,

> Again, I think that this is not a job for Ethereal, but is a job for
> another tool that understands the structure of the protocols involved.  It
> would sort through the data and apply some heuristics to spot anomalies.
> 
> Such a tool, and Ethereal, would be helped if there was an underlying
> library that knew how to decode packets, so each higher level tool could
> concentrate on its own job. In the case of Ethereal, that job is to display
> the decoded packets.

Such a library also would make an RMON-2 subagent (like btng) or an IDS
tool (like snort) much easier :-)

Regards,
Jochen