Update : I tried to parse my PCAP file with zeek (zeek -C -r sample.pcap). There are 7 lines in the http.log file : so there is clearly an issue with scapy. In fact I think the problem is in the dissection of the packets in order to identify a HTTPResponse.
======
I am trying to map HTTP Requests to HTTP Responses from a pcap file. To do that I use the sniff() function with TCPSession.
My code is the following :
from scapy.all import *
load_layer("http")
pcap_file = "sample.pcap"
def callback_method(packet):
if packet.haslayer('HTTPRequest'):
request_list.append(packet)
elif packet.haslayer('HTTPResponse'):
response_list.append(packet)
else:
logging.debug("other")
logging.basicConfig(level=logging.INFO, format='%(asctime)s - %(levelname)s - %(message)s', datefmt='%d-%b-%y %H:%M:%S')
request_list = []
response_list = []
sessions = sniff(offline=pcap_file, prn=callback_method, session=TCPSession).sessions()
logging.info(f"Number of HTTPRequest: {len(request_list)}")
logging.info(f"Number of HTTPResponse: {len(response_list)}")
for http_request in request_list:
for http_response in response_list:
if http_response.answers(http_request) == 1:
logging.info(f"HTTPResponse found !!!")
break
The output is :
06-Jun-22 14:46:04 - INFO - Number of HTTPRequest: 7
06-Jun-22 14:46:04 - INFO - Number of HTTPResponse : 7
06-Jun-22 14:46:04 - INFO - HTTPResponse found !!!
06-Jun-22 14:46:04 - INFO - HTTPResponse found !!!
06-Jun-22 14:46:04 - INFO - HTTPResponse found !!!
06-Jun-22 14:46:04 - INFO - HTTPResponse found !!!
I don’t understand the result : there are 7 requests and 7 corresponding responses in the pcap file, but my code has only found 4 pairs (request, response). It seems that the http_response.answers(http_request) doesn’t work sometimes ?
When I use tshark => tshark -r "$1" -2 -R "tcp and (http.request or http.response)" -T fields -e tcp.stream | sort -n | uniq
the output is =>
20
20
90
90
91
91
99
100
100
99
108
108
122
122
So there are really 7 pairs (requests, responses) (streams 20, 90, 91, 99, 100, 108, 122) ...