2 * dcerpcstat 2002 Ronnie Sahlberg
4 * $Id: tap-dcerpcstat.c,v 1.6 2003/09/03 10:10:17 sahlberg Exp $
6 * Ethereal - Network traffic analyzer
7 * By Gerald Combs <gerald@ethereal.com>
8 * Copyright 1998 Gerald Combs
10 * This program is free software; you can redistribute it and/or
11 * modify it under the terms of the GNU General Public License
12 * as published by the Free Software Foundation; either version 2
13 * of the License, or (at your option) any later version.
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
20 * You should have received a copy of the GNU General Public License
21 * along with this program; if not, write to the Free Software
22 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
31 #ifdef HAVE_SYS_TYPES_H
32 # include <sys/types.h>
36 #include "epan/packet_info.h"
38 #include "packet-dcerpc.h"
41 /* used to keep track of statistics for a specific procedure */
42 typedef struct _rpc_procedure_t {
50 /* used to keep track of the statistics for an entire program interface */
51 typedef struct _rpcstat_t {
56 guint32 num_procedures;
57 rpc_procedure_t *procedures;
63 dcerpcstat_packet(void *prs, packet_info *pinfo, epan_dissect_t *edt _U_, void *pri)
73 if(!ri->call_data->req_frame){
74 /* we have not seen the request so we dont know the delta*/
77 if(ri->call_data->opnum>=rs->num_procedures){
78 /* dont handle this since its outside of known table */
82 /* we are only interested in reply packets */
87 /* we are only interested in certain program/versions */
88 if( (ri->call_data->uuid.Data1!=rs->uuid.Data1)
89 ||(ri->call_data->uuid.Data2!=rs->uuid.Data2)
90 ||(ri->call_data->uuid.Data3!=rs->uuid.Data3)
91 ||(ri->call_data->uuid.Data4[0]!=rs->uuid.Data4[0])
92 ||(ri->call_data->uuid.Data4[1]!=rs->uuid.Data4[1])
93 ||(ri->call_data->uuid.Data4[2]!=rs->uuid.Data4[2])
94 ||(ri->call_data->uuid.Data4[3]!=rs->uuid.Data4[3])
95 ||(ri->call_data->uuid.Data4[4]!=rs->uuid.Data4[4])
96 ||(ri->call_data->uuid.Data4[5]!=rs->uuid.Data4[5])
97 ||(ri->call_data->uuid.Data4[6]!=rs->uuid.Data4[6])
98 ||(ri->call_data->uuid.Data4[7]!=rs->uuid.Data4[7])
99 ||(ri->call_data->ver!=rs->ver)){
103 rp=&(rs->procedures[ri->call_data->opnum]);
105 /* calculate time delta between request and reply */
106 delta.secs=pinfo->fd->abs_secs-ri->call_data->req_time.secs;
107 delta.nsecs=pinfo->fd->abs_usecs*1000-ri->call_data->req_time.nsecs;
109 delta.nsecs+=1000000000;
114 rp->max.secs=delta.secs;
115 rp->max.nsecs=delta.nsecs;
119 rp->min.secs=delta.secs;
120 rp->min.nsecs=delta.nsecs;
123 if( (delta.secs<rp->min.secs)
124 ||( (delta.secs==rp->min.secs)
125 &&(delta.nsecs<rp->min.nsecs) ) ){
126 rp->min.secs=delta.secs;
127 rp->min.nsecs=delta.nsecs;
130 if( (delta.secs>rp->max.secs)
131 ||( (delta.secs==rp->max.secs)
132 &&(delta.nsecs>rp->max.nsecs) ) ){
133 rp->max.secs=delta.secs;
134 rp->max.nsecs=delta.nsecs;
137 rp->tot.secs += delta.secs;
138 rp->tot.nsecs += delta.nsecs;
139 if(rp->tot.nsecs>1000000000){
140 rp->tot.nsecs-=1000000000;
150 dcerpcstat_draw(void *prs)
160 printf("===================================================================\n");
161 printf("%s Version %d.%d RTT Statistics:\n", rs->prog, rs->ver&0xff,rs->ver>>8);
162 printf("Filter: %s\n",rs->filter?rs->filter:"");
163 printf("Procedure Calls Min RTT Max RTT Avg RTT\n");
164 for(i=0;i<rs->num_procedures;i++){
165 /* scale it to units of 10us.*/
166 /* for long captures with a large tot time, this can overflow on 32bit */
167 td=(int)rs->procedures[i].tot.secs;
168 td=td*100000+(int)rs->procedures[i].tot.nsecs/10000;
169 if(rs->procedures[i].num){
170 td/=rs->procedures[i].num;
175 printf("%-25s %6d %3d.%05d %3d.%05d %3d.%05d\n",
176 rs->procedures[i].proc,
177 rs->procedures[i].num,
178 (int)rs->procedures[i].min.secs,rs->procedures[i].min.nsecs/10000,
179 (int)rs->procedures[i].max.secs,rs->procedures[i].max.nsecs/10000,
183 printf("===================================================================\n");
189 dcerpcstat_init(char *optarg)
192 guint32 i, max_procs;
193 dcerpc_sub_dissector *procs;
195 int d1,d2,d3,d40,d41,d42,d43,d44,d45,d46,d47;
199 GString *error_string;
201 if(sscanf(optarg,"dcerpc,rtt,%08x-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x,%d.%d%n", &d1,&d2,&d3,&d40,&d41,&d42,&d43,&d44,&d45,&d46,&d47,&major,&minor,&pos)==13){
219 fprintf(stderr, "tethereal: invalid \"-z dcerpc,rtt,<uuid>,<major version>.<minor version>[,<filter>]\" argument\n");
224 rs=g_malloc(sizeof(rpcstat_t));
225 rs->prog=dcerpc_get_proto_name(&uuid, (minor<<8)|(major&0xff) );
228 fprintf(stderr,"tethereal: dcerpcstat_init() Protocol with uuid:%08x-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x v%d.%d not supported\n",uuid.Data1,uuid.Data2,uuid.Data3,uuid.Data4[0],uuid.Data4[1],uuid.Data4[2],uuid.Data4[3],uuid.Data4[4],uuid.Data4[5],uuid.Data4[6],uuid.Data4[7],major,minor);
231 procs=dcerpc_get_proto_sub_dissector(&uuid, (minor<<8)|(major&0xff) );
233 rs->ver=(minor<<8)|(major&0xff);
236 rs->filter=g_malloc(strlen(filter)+1);
237 strcpy(rs->filter, filter);
242 for(i=0,max_procs=0;procs[i].name;i++){
243 if(procs[i].num>max_procs){
244 max_procs=procs[i].num;
247 rs->num_procedures=max_procs+1;
248 rs->procedures=g_malloc(sizeof(rpc_procedure_t)*(rs->num_procedures+1));
249 for(i=0;i<rs->num_procedures;i++){
251 rs->procedures[i].proc="unknown";
252 for(j=0;procs[j].name;j++){
254 rs->procedures[i].proc=procs[j].name;
257 rs->procedures[i].num=0;
258 rs->procedures[i].min.secs=0;
259 rs->procedures[i].min.nsecs=0;
260 rs->procedures[i].max.secs=0;
261 rs->procedures[i].max.nsecs=0;
262 rs->procedures[i].tot.secs=0;
263 rs->procedures[i].tot.nsecs=0;
266 error_string=register_tap_listener("dcerpc", rs, filter, NULL, dcerpcstat_packet, dcerpcstat_draw);
268 /* error, we failed to attach to the tap. clean up */
269 g_free(rs->procedures);
273 fprintf(stderr, "tethereal: Couldn't register dcerpc,rtt tap: %s\n",
275 g_string_free(error_string, TRUE);
281 register_tap_listener_dcerpcstat(void)
283 register_ethereal_tap("dcerpc,rtt,", dcerpcstat_init);