Problem to map offline HTTP response to HTTP request with Scapy and the answers method

Viewed 46

Update : I tried to parse my PCAP file with zeek (zeek -C -r sample.pcap). There are 7 lines in the http.log file : so there is clearly an issue with scapy. In fact I think the problem is in the dissection of the packets in order to identify a HTTPResponse.

======

I am trying to map HTTP Requests to HTTP Responses from a pcap file. To do that I use the sniff() function with TCPSession.

My code is the following :

from scapy.all import *

load_layer("http")

pcap_file = "sample.pcap"


def callback_method(packet):
    if packet.haslayer('HTTPRequest'):
        request_list.append(packet)
    elif packet.haslayer('HTTPResponse'):
        response_list.append(packet)
    else:
        logging.debug("other")


logging.basicConfig(level=logging.INFO, format='%(asctime)s - %(levelname)s - %(message)s', datefmt='%d-%b-%y %H:%M:%S')

request_list = []
response_list = []

sessions = sniff(offline=pcap_file, prn=callback_method, session=TCPSession).sessions()

logging.info(f"Number of HTTPRequest: {len(request_list)}")
logging.info(f"Number of HTTPResponse: {len(response_list)}")

for http_request in request_list:
    for http_response in response_list:
        if http_response.answers(http_request) == 1:
            logging.info(f"HTTPResponse found !!!")
            break

The output is :

06-Jun-22 14:46:04 - INFO - Number of HTTPRequest: 7
06-Jun-22 14:46:04 - INFO - Number of HTTPResponse : 7
06-Jun-22 14:46:04 - INFO - HTTPResponse found !!!
06-Jun-22 14:46:04 - INFO - HTTPResponse found !!!
06-Jun-22 14:46:04 - INFO - HTTPResponse found !!!
06-Jun-22 14:46:04 - INFO - HTTPResponse found !!!

I don’t understand the result : there are 7 requests and 7 corresponding responses in the pcap file, but my code has only found 4 pairs (request, response). It seems that the http_response.answers(http_request) doesn’t work sometimes ?

When I use tshark => tshark -r "$1" -2 -R "tcp and (http.request or http.response)" -T fields -e tcp.stream | sort -n | uniq the output is =>

20
20
90
90
91
91
99
100
100
99
108
108
122
122

So there are really 7 pairs (requests, responses) (streams 20, 90, 91, 99, 100, 108, 122) ...

0 Answers
Related