Talk With an Expert

PCAP Next Generation: Is Your Sniffer Up to Snuff?

PCAP Next Generation: Is Your Sniffer Up to Snuff? (PDF, 4.82MB)Published: 16 Mar, 2018
Created by
Scott D. Fether
The PCAP file format is widely used for packet capture within the network and security industry, but it is not the only standard. The PCAP Next Generation (PCAPng) Capture File Format is a refreshing improvement that adds extensibility, portability, and the ability to merge and append data to a wire trace. While Wireshark has led the way in supporting the new format, other tools have been slow to follow. With advantages such as the ability to capture from multiple interfaces, improved time resolution, and the ability to add per-packet comments, support for the PCAPng format should be developing more quickly than it has. This paper describes the new standard, displays methods to take advantage of new features, introduces scripting that can make the format useable, and makes the argument that migration to PCAPng is necessary.
PCAP Next Generation: Is Your Sniffer Up to Snuff?