寻求匹配TCP选项类型为8的tcpdump过滤规则解决方案
First, let's figure out why your tcp[22] = 8 filter didn't work: the position of TCP options isn't fixed. The TCP header length varies depending on which options are included (like MSS, window scale, etc.), so hardcoding an offset like 22 will only work if the timestamp option lands in that exact spot every time—which rarely happens.
Correct tcpdump Filter for TCP Option Kind 8
To reliably capture all packets with TCP option kind 8 (the timestamp option), use this filter that dynamically accounts for the variable TCP header length:
tcp[20:((tcp[12] >> 2) * 4) - 20] & 0xff = 8
Let's break this down step by step:
tcp[12] >> 2: Extracts the TCP header length. The 4-bit "data offset" field in the TCP header uses 32-bit words as units, so shifting right 2 bits converts it to bytes (equivalent to multiplying by 4).((tcp[12] >> 2) * 4) - 20: Calculates the total length of the options section—since the first 20 bytes are the fixed TCP header, we subtract that from the total header length to get just the options part.tcp[20:...]: Targets the entire options section starting at offset 20 (right after the fixed header).& 0xff = 8: Checks if any byte in the options section equals 8 (the option kind we're looking for).
Alternative: Narrow to SYN Packets with Timestamp Option
If you only care about SYN packets (which commonly include timestamp options for round-trip time calculation), you can add a SYN flag filter to narrow results:
tcp[tcpflags] & tcp-syn != 0 and tcp[20:((tcp[12] >> 2) * 4) - 20] & 0xff = 8
内容的提问来源于stack exchange,提问作者Nitzan Davari

