diff --git a/doc/windivert.html b/doc/windivert.html index d2cd589..176fa0d 100644 --- a/doc/windivert.html +++ b/doc/windivert.html @@ -16,16 +16,17 @@
+
+typedef enum
+{
+ WINDIVERT_LAYER_NETWORK = 0,
+ WINDIVERT_LAYER_NETWORK_FORWARD,
+ WINDIVERT_LAYER_FLOW,
+ WINDIVERT_LAYER_SOCKET,
+ WINDIVERT_LAYER_REFLECT,
+} WINDIVERT_LAYER, *PWINDIVERT_LAYER;
+
+ |
+WinDivert supports several layers for diverting or capturing +network packets/events. +Each layer has its own capabilities, such as the ability to block +events or to inject new events, etc. +The list of supported WinDivert layers is summarized below: +
++
| Layer | +Capability | +Description | +|||
|---|---|---|---|---|---|
| + | ++Block? + | ++Inject? + | ++Data? + | ++PID? + | ++ | +
| +WINDIVERT_LAYER_NETWORK + | +✔ | ✔ | ✔ | + | +Network packets to/from the local machine. + | +
| +WINDIVERT_LAYER_NETWORK_FORWARD + | +✔ | ✔ | ✔ | + | +Network packets passing through the local machine. + | +
| +WINDIVERT_LAYER_FLOW + | +✔ | ++Network flow established/deleted events. + | +|||
| +WINDIVERT_LAYER_SOCKET + | +✔ | ✔ | ++Socket operation events. + | +||
| +WINDIVERT_LAYER_REFLECT + | +✔ | ✔ | ++WinDivert handle events. + | +||
+Here, the layer capabilities are: +
+
+Both WINDIVERT_LAYER_NETWORK and
+WINDIVERT_LAYER_NETWORK_FORWARD represent the traditional
+WinDivert layers, allowing the user application to capture/block/inject
+network packets passing to/from/through the local machine.
+This layer only supports one event, namely:
+
+The WINDIVERT_LAYER_FLOW layer captures information about
+network flow establishment/deletion events.
+Here, a flow represents a packet flow
, meaning either a
+TCP connection, or an implicit flow
created by the first sent/received
+packet for non-TCP traffic, e.g., UDP.
+The WINDIVERT_LAYER_FLOW layer supports two events:
+
+Flows can be captured, but never blocked or injected. +Process ID information is available at this layer. +Due to technical limitations, the +WINDIVERT_LAYER_FLOW layer cannot capture events that +occurred before the WinDivert handle was opened. +
++The WINDIVERT_LAYER_SOCKET layer captures/blocks events that +correspond to socket operations, such as: +
++Socket events can be blocked but not injected. +Process ID information is available at this layer. +Due to technical limitations, the +WINDIVERT_LAYER_SOCKET layer cannot capture events that +occurred before the WinDivert handle was opened. +
++Finally, the WINDIVERT_LAYER_REFLECT layer captures events related +to WinDivert itself, such as: +
+
+These events can be captured, but not injected nor blocked.
+Process ID information is available at this layer,
+meaning that it is possible to determine which (if any) process is using
+WinDivert.
+The layer also returns a pseudo packet
that encodes the filter string
+associated with the event.
+The WINDIVERT_LAYER_REFLECT layer can also capture events that
+occurred before the handle was opened.
+
typedef struct
{
- INT64 Timestamp;
UINT32 IfIdx;
UINT32 SubIfIdx;
- UINT8 Direction:1;
- UINT8 Loopback:1;
- UINT8 Impostor:1;
- UINT8 PseudoIPChecksum:1;
- UINT8 PseudoTCPChecksum:1;
- UINT8 PseudoUDPChecksum:1;
+} WINDIVERT_DATA_NETWORK, *PWINDIVERT_DATA_NETWORK;
+
+typedef struct
+{
+ UINT32 ProcessId;
+ UINT32 LocalAddr[4];
+ UINT32 RemoteAddr[4];
+ UINT16 LocalPort;
+ UINT16 RemotePort;
+ UINT8 Protocol;
+} WINDIVERT_DATA_FLOW, *PWINDIVERT_DATA_FLOW;
+
+typedef struct
+{
+ UINT32 ProcessId;
+ UINT32 LocalAddr[4];
+ UINT32 RemoteAddr[4];
+ UINT16 LocalPort;
+ UINT16 RemotePort;
+ UINT8 Protocol;
+} WINDIVERT_DATA_SOCKET, *PWINDIVERT_DATA_SOCKET;
+
+typedef struct
+{
+ INT64 Timestamp;
+ UINT32 ProcessId;
+ WINDIVERT_LAYER Layer;
+ UINT64 Flags;
+ INT16 Priority;
+} WINDIVERT_DATA_REFLECT, *PWINDIVERT_DATA_REFLECT;
+
+typedef struct
+{
+ INT64 Timestamp;
+ UINT64 Layer:8;
+ UINT64 Event:8;
+ UINT64 Outbound:1;
+ UINT64 Loopback:1;
+ UINT64 Impostor:1;
+ UINT64 IPv6:1;
+ UINT64 PseudoIPChecksum:1;
+ UINT64 PseudoTCPChecksum:1;
+ UINT64 PseudoUDPChecksum:1;
+ union
+ {
+ WINDIVERT_DATA_NETWORK Network;
+ WINDIVERT_DATA_FLOW Flow;
+ WINDIVERT_DATA_SOCKET Socket;
+ WINDIVERT_DATA_REFLECT Reflect;
+ };
} WINDIVERT_ADDRESS, *PWINDIVERT_ADDRESS;
|
HANDLE WinDivertOpen( @@ -572,7 +794,7 @@ Note that only one of WINDIVERT_FLAG_SNIFF or -
|