Repository navigation
Add PCAP / PCAPNG packet-capture parser - #39
Conversation
New PcapParser in ax-normalize. Decodes a capture to one row per packet: the marquee timestamp column (epoch seconds, Float) for beaconing/C2 detection via cadence on inter-arrival times, plus length (original) and caplen for volume point spikes, and src_ip/dst_ip/ip_proto (Ethernet or raw IPv4/IPv6, via etherparse) for mv over per-packet features. The container is decoded by pcap-parser, covering both legacy PCAP and PCAPNG, either byte order, and microsecond or nanosecond resolution: the legacy header sets the link type and ns/us precision; the PCAPNG interface-description block sets the link type and timestamp resolution, and enhanced/simple packet blocks are decoded accordingly. L3 decode is best-effort — an unsupported link type or an undecodable packet just yields no L3 columns. Binary magic (the four legacy magics plus the PCAPNG section-header magic), confidence MAGIC; extensions .pcap/.pcapng/.cap. Behind the default-on pcap feature (mirrors the polars/evtx binary readers), so the text-only build stays lean. Hand-built legacy + PCAPNG fixtures roundtrip; a real Ethernet/IPv4/UDP and IPv6/UDP frame exercise the L3 decode; malformed input is a clean Parse error. Mutation gate: 0 surviving mutants on the new file. Closes #15 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Warning Review limit reached
More reviews will be available in 6 minutes and 55 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (4)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Implements the PCAP / PCAPNG plugin — issue #15 (binary, hard).
What
Decodes a capture to one row per packet with the columns the detectors need:
timestamp(epoch seconds,Float) — the marquee input forbeaconing/C2 detection via
cadenceon inter-arrival times;length(original) +caplen— volumepointspikes;src_ip/dst_ip/ip_proto(Ethernet or raw IPv4/IPv6, viaetherparse)—
mvover per-packet features.The container is decoded by
pcap-parser, covering both legacy PCAP andPCAPNG, either byte order, and µs or ns resolution: the legacy header sets
the link type + precision; the PCAPNG interface block sets the link type +
timestamp resolution; enhanced and simple packet blocks decode accordingly. L3
decode is best-effort — an unsupported link type or undecodable packet just
yields no L3 columns (the packet keeps its timestamp/length).
Routing
confidence
MAGIC; extensions.pcap/.pcapng/.cap.Feature gating
Behind the default-on
pcapfeature (mirrors the polars/evtx binaryreaders), so the text-only
--no-default-featuresbuild stays lean.Testing
Hand-built legacy + PCAPNG fixtures roundtrip (timestamps, original vs captured
length, ns precision, PCAPNG µs resolution); real Ethernet/IPv4/UDP and IPv6/UDP
frames exercise the L3 decode (incl. the raw-IP
from_ippath); malformed inputis a clean
AxError::Parse.Gates
fmt/clippy -D warnings/ full workspace tests green (default and--no-default-features).pcap.rs.pcapand the C2 regularity isflagged by
cadenceontimestamp(exit 1).Closes #15
🤖 Generated with Claude Code