|Original author(s)||Daniel Borkmann|
|Developer(s)||Daniel Borkmann, Tobias Klauser, Herbert Haas, Emmanuel Roullit, Markus Amend and many others|
|Initial release||December, 2009|
0.6.8 / 11 January 2021
netsniff-ng is a free Linux network analyzer and networking toolkit originally written by Daniel Borkmann. Its gain of performance is reached by zero-copy mechanisms for network packets (RX_RING, TX_RING), so that the Linux kernel does not need to copy packets from kernel space to user space via system calls such as
recvmsg(). libpcap, starting with release 1.0.0, also supports the zero-copy mechanism on Linux for capturing (RX_RING), so programs using libpcap also use that mechanism on Linux.
netsniff-ng was initially created as a network sniffer with support of the Linux kernel packet-mmap interface for network packets, but later on, more tools have been added to make it a useful toolkit such as the iproute2 suite, for instance. Through the kernel's zero-copy interface, efficient packet processing can be reached even on commodity hardware. For instance, Gigabit Ethernet wire-speed has been reached with netsniff-ng's trafgen. The netsniff-ng toolkit does not depend on the libpcap library. Moreover, no special operating system patches are needed to run the toolkit. netsniff-ng is free software and has been released under the terms of the GNU General Public License version 2.
The toolkit currently consists of a network analyzer, packet capturer and replayer, a wire-rate traffic generator, an encrypted multiuser IP tunnel, a Berkeley Packet Filter compiler, networking statistic tools, an autonomous system trace route and more:
- netsniff-ng, a zero-copy analyzer, packet capturer and replayer, itself supporting the pcap file format
- trafgen, a zero-copy wire-rate traffic generator
- mausezahn, a packet generator and analyzer for HW/SW appliances with a Cisco-CLI
- bpfc, a Berkeley Packet Filter compiler
- ifpps, a top-like kernel networking statistics tool
- flowtop, a top-like netfilter connection tracking tool with Geo-IP information
- curvetun, a lightweight multiuser IP tunnel based on elliptic curve cryptography
- astraceroute, an autonomous system trace route utility with Geo-IP information
Distribution specific packages are available for all major operating system distributions such as Debian or Fedora Linux. It has also been added to Xplico's Network Forensic Toolkit, GRML Linux, SecurityOnion, and to the Network Security Toolkit. The netsniff-ng toolkit is also used in academia.
Basic commands working in netsniff-ng
In these examples, it is assumed that eth0 is the used network interface. Programs in the netsniff-ng suite accept long options, e.g., --in ( -i ), --out ( -o ), --dev ( -d ).
astraceroute -d eth0 -N -S -H <host e.g., netsniff-ng.org>
- For kernel networking statistics within promiscuous mode:
ifpps -d eth0 -p
- For high-speed network packet traffic generation, trafgen.txf is the packet configuration:
trafgen -d eth0 -c trafgen.txf
- For compiling a Berkeley Packet Filter fubar.bpf:
- For live-tracking of current TCP connections (including protocol, application name, city and country of source and destination):
- For efficiently dumping network traffic in a pcap file:
netsniff-ng -i eth0 -o dump.pcap -s -b 0
- Comparison of packet analyzers
- Packet generator
- Traffic generation model
- "Release 0.6.8". 11 January 2021. Retrieved 13 January 2021.
- "netsniff-ng license".
- https://api.github.com/repos/borkmann/netsniff-ng; retrieved: 29 July 2018.
- "Description of the Linux packet-mmap mechanism". Retrieved 6 November 2011.
- "netsniff-ng Homepage, Abstract, Zero-copy". Archived from the original on 8 September 2016. Retrieved 6 November 2011.
- "Network Security Toolkit Article about trafgen's performance capabilities". Retrieved 6 November 2011.
- "Developer's Blog about trafgen's Performance". 16 October 2011. Archived from the original on 25 April 2012. Retrieved 6 November 2011.
- "netsniff-ng README". Retrieved 16 February 2018.
- "netsnif-ng in Debian".
- "Xplico support of netsniff-ng". Retrieved 6 November 2011.
- "Security Onion 12.04 RC1 Available Now!". Retrieved 16 December 2012.
- "Network Security Toolkit adds netsniff-ng". Retrieved 6 November 2011.
- "netsniff-ng's trafgen at University of Napoli Federico II". Retrieved 7 November 2011.
- "netsniff-ng's trafgen at Columbia University". Retrieved 7 November 2011.
- "netsniff-ng FAQ declining a port to Microsoft Windows". Retrieved 21 June 2015.