You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何Scapy PcapReader读取非标准端口Diameter包时显示Raw而非DiamG?

解决Scapy无法识别非标准端口Diameter流量的问题

Scapy默认只将TCP 3868端口与Diameter(DiamG层)关联,所以非标准端口的Diameter流量会被识别为Raw层。要解决这个问题,有两种可行方案:

方案一:添加非标准端口到Scapy的TCP协议映射表

直接修改Scapy的TCP端口映射,让它把目标非标准端口的流量自动解析为Diameter协议。

代码示例

from scapy.all import PcapReader, DiamG
from scapy.layers.tcp import TCP

# 替换为你的非标准Diameter端口,比如示例中的50124
TARGET_PORT = 50124
# 将端口与DiamG协议绑定
TCP.payload_map[TARGET_PORT] = DiamG

workdir = "你的工作目录路径"
file = "非标准端口的pcap文件名"

with PcapReader(f'{workdir}/data/{file}') as pr:
    for p in pr:
        if p.haslayer(DiamG):
            # 现在可直接访问DiamG层及AVP
            print(p[DiamG])
            # 示例:提取Session-Id AVP
            session_id = p[DiamG].get_avp("Session-Id")
            if session_id:
                print(f"Session-Id: {session_id}")

方案二:手动解析Raw层为DiamG

如果不想修改全局端口映射,可以在遍历数据包时,针对目标端口的Raw数据手动解析为DiamG层。

代码示例

from scapy.all import PcapReader, DiamG

TARGET_PORT = 50124
workdir = "你的工作目录路径"
file = "非标准端口的pcap文件名"

with PcapReader(f'{workdir}/data/{file}') as pr:
    for p in pr:
        # 检查是否是目标端口的TCP包且带有Raw层
        if p.haslayer("TCP") and p.haslayer("Raw"):
            tcp_layer = p["TCP"]
            if tcp_layer.dport == TARGET_PORT or tcp_layer.sport == TARGET_PORT:
                # 手动将Raw层负载解析为DiamG协议
                diam_pkt = DiamG(p["Raw"].load)
                print(diam_pkt)
                # 示例:提取Auth-Session-State AVP
                auth_state = diam_pkt.get_avp("Auth-Session-State")
                if auth_state:
                    print(f"Auth-Session-State: {auth_state}")

两种方案都能正常提取非标准端口Diameter流量中的AVP信息,可根据需求选择使用。

内容的提问来源于stack exchange,提问作者Jairo Caicedo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 12:02:33