ArticleslgStudy

computer science

Netsniff-ng

Netsniff-ng is a computer science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Netsniff-ng rather than just read about it. In short: netsniff-ng is a free Linux network analyzer and networking toolkit originally written by Daniel Borkmann. Its gain of performance is reached by zero-copy mechanisms for network packets (RX_RING, TX_RING), so that the Linux kernel does not need to copy packets from kernel space to user space via system calls such as recvmsg(). libpcap, starting with release 1.0.0, also supports the zero-copy mechanism on Linux for c…

Netsniff-ng — main illustration
Netsniff-ng — illustration

Key takeaways

  • Netsniff-ng belongs to computer science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Netsniff-ng to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Netsniff-ng from memory before moving on to harder problems.

Reference excerpt

netsniff-ng is a free Linux network analyzer and networking toolkit originally written by Daniel Borkmann. Its gain of performance is reached by zero-copy mechanisms for network packets (RX_RING, TX_RING), so that the Linux kernel does not need to copy packets from kernel space to user space via system calls such as recvmsg(). libpcap, starting with release 1.0.0, also supports the zero-copy mechanism on Linux for capturing (RX_RING), so programs using libpcap also use that mechanism on Linux.

Overview netsniff-ng was initially created as a network sniffer with support of the Linux kernel packet-mmap interface for network packets, but later on, more tools have been added to make it a useful toolkit such as the iproute2 suite, for instance. Through the kernel's zero-copy interface, efficient packet processing can be reached even on commodity hardware. For instance, Gigabit Ethernet wire-speed has been reached with netsniff-ng's trafgen. The netsniff-ng toolkit does not depend on the libpcap library. Moreover, no special operating system patches are needed to run the toolkit. netsniff-ng is free software and has been released under the terms of the GNU General Public License version 2. The toolkit currently consists of a network analyzer, packet capturer and replayer, a wire-rate traffic generator, an encrypted multiuser IP tunnel, a Berkeley Packet Filter compiler, networking statistic tools, an autonomous system trace route and more:

netsniff-ng: a zero-copy analyzer, packet capturer and replayer, itself supporting the pcap file format trafgen: a zero-copy wire-rate traffic generator mausezahn: a packet generator and analyzer for HW/SW appliances with a Cisco-CLI bpfc: a Berkeley Packet Filter (BPF) compiler ifpps: a top-like kernel networking statistics tool flowtop: a top-like netfilter connection tracking tool with Geo-IP information curvetun: a lightweight multiuser IP tunnel based on elliptic-curve cryptography astraceroute: an autonomous system trace route utility with Geo-IP information Distribution specific packages are available for all major operating system distributions such as Debian or Fedora Linux. It has also been added to Xplico's Network Forensic Toolkit, GRML Linux, Security Onion, and to the Network Security Toolkit. The netsniff-ng toolkit is also used in academia.

Basic commands working in netsniff-ng In these examples, it is assumed that eth0 is the used network interface. Programs in the netsniff-ng suite accept long options, e.g. --in ( -i ), --out ( -o ), --dev ( -d ).

For geographical AS TCP SYN probe trace route to a website:

For kernel networking statistics within promiscuous mode:

For high-speed network packet traffic generation, trafgen.txf is the packet configuration:

For compiling a Berkeley Packet Filter fubar.bpf:

For live-tracking of current TCP connections (including protocol, application name, city and country of source and destination):

For efficiently dumping network traffic in a pcap file:

Platforms The netsniff-ng toolkit currently runs only on Linux systems. Its developers decline a port to Microsoft Windows.

See also Comparison of packet analyzers OpenVPN Packet generator Tcpdump Traceroute Traffic generation model Wireshark Xplico

References

External links Official netsniff-ng website

Illustrations

Netsniff-ng illustration
Netsniff-ng illustration

Worked examples

Example 1 — a first encounter with Netsniff-ng

Start with the simplest possible case. Write down what Netsniff-ng claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In computer science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Netsniff-ng before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Netsniff-ng ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Netsniff-ng

In research
Netsniff-ng appears in computer science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Netsniff-ng in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Netsniff-ng is common in secondary-school and first-year university syllabi. It links to neighbouring topics Command-line software, Free network-related software, Free network management software, so understanding it makes those chapters shorter.
In everyday life
Look for Netsniff-ng outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Netsniff-ng in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Netsniff-ng means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Netsniff-ng out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Netsniff-ng in simple terms?

netsniff-ng is a free Linux network analyzer and networking toolkit originally written by Daniel Borkmann. Its gain of performance is reached by zero-copy mechanisms for network packets (RX_RING, TX_RING), so that the Linux kernel does not need to copy packets from kernel space to user space via sy…

Why does Netsniff-ng matter?

Because it connects several computer science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Netsniff-ng?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Netsniff-ng.

Tags

  • Command-line software
  • Free network-related software
  • Free network management software
  • Free software programmed in C
  • Linux-only free software
  • Network analyzers
  • Unix network-related software

Keep exploring