From 1496a0fe06ade99b908ca4d5eb9f5953714e96c1 Mon Sep 17 00:00:00 2001
From: basil00
+WinDivert supports several layers for diverting or capturing
+network packets/events.
+Each layer has its own capabilities, such as the ability to block
+events or to inject new events, etc.
+The list of supported WinDivert layers is summarized below:
+
+
-
@@ -238,20 +239,241 @@ To use the WinDivert package, a program/application must:
library.
-
5.1 WINDIVERT_ADDRESS
+5.1 WINDIVERT_LAYER
+
+
+
+typedef enum
+{
+ WINDIVERT_LAYER_NETWORK = 0,
+ WINDIVERT_LAYER_NETWORK_FORWARD,
+ WINDIVERT_LAYER_FLOW,
+ WINDIVERT_LAYER_SOCKET,
+ WINDIVERT_LAYER_REFLECT,
+} WINDIVERT_LAYER, *PWINDIVERT_LAYER;
+
+
+
+
+
+
+Layer
+Capability
+Description
+
+
+
+
+
+Block?
+
+
+Inject?
+
+
+Data?
+
+
+PID?
+
+
+
+
+
+
+WINDIVERT_LAYER_NETWORK
+
+✔ ✔ ✔
+
+Network packets to/from the local machine.
+
+
+
+
+WINDIVERT_LAYER_NETWORK_FORWARD
+
+✔ ✔ ✔
+
+Network packets passing through the local machine.
+
+
+
+
+WINDIVERT_LAYER_FLOW
+
+✔
+
+Network flow established/deleted events.
+
+
+
+
+WINDIVERT_LAYER_SOCKET
+
+✔ ✔
+
+Socket operation events.
+
+
+
+
+WINDIVERT_LAYER_REFLECT
+
+✔ ✔
+
+WinDivert handle events.
+
+
+Here, the layer capabilities are: +
+
+Both WINDIVERT_LAYER_NETWORK and
+WINDIVERT_LAYER_NETWORK_FORWARD represent the traditional
+WinDivert layers, allowing the user application to capture/block/inject
+network packets passing to/from/through the local machine.
+This layer only supports one event, namely:
+
+The WINDIVERT_LAYER_FLOW layer captures information about
+network flow establishment/deletion events.
+Here, a flow represents a packet flow
, meaning either a
+TCP connection, or an implicit flow
created by the first sent/received
+packet for non-TCP traffic, e.g., UDP.
+The WINDIVERT_LAYER_FLOW layer supports two events:
+
+Flows can be captured, but never blocked or injected. +Process ID information is available at this layer. +Due to technical limitations, the +WINDIVERT_LAYER_FLOW layer cannot capture events that +occurred before the WinDivert handle was opened. +
++The WINDIVERT_LAYER_SOCKET layer captures/blocks events that +correspond to socket operations, such as: +
++Socket events can be blocked but not injected. +Process ID information is available at this layer. +Due to technical limitations, the +WINDIVERT_LAYER_SOCKET layer cannot capture events that +occurred before the WinDivert handle was opened. +
++Finally, the WINDIVERT_LAYER_REFLECT layer captures events related +to WinDivert itself, such as: +
+
+These events can be captured, but not injected nor blocked.
+Process ID information is available at this layer,
+meaning that it is possible to determine which (if any) process is using
+WinDivert.
+The layer also returns a pseudo packet
that encodes the filter string
+associated with the event.
+The WINDIVERT_LAYER_REFLECT layer can also capture events that
+occurred before the handle was opened.
+
typedef struct
{
- INT64 Timestamp;
UINT32 IfIdx;
UINT32 SubIfIdx;
- UINT8 Direction:1;
- UINT8 Loopback:1;
- UINT8 Impostor:1;
- UINT8 PseudoIPChecksum:1;
- UINT8 PseudoTCPChecksum:1;
- UINT8 PseudoUDPChecksum:1;
+} WINDIVERT_DATA_NETWORK, *PWINDIVERT_DATA_NETWORK;
+
+typedef struct
+{
+ UINT32 ProcessId;
+ UINT32 LocalAddr[4];
+ UINT32 RemoteAddr[4];
+ UINT16 LocalPort;
+ UINT16 RemotePort;
+ UINT8 Protocol;
+} WINDIVERT_DATA_FLOW, *PWINDIVERT_DATA_FLOW;
+
+typedef struct
+{
+ UINT32 ProcessId;
+ UINT32 LocalAddr[4];
+ UINT32 RemoteAddr[4];
+ UINT16 LocalPort;
+ UINT16 RemotePort;
+ UINT8 Protocol;
+} WINDIVERT_DATA_SOCKET, *PWINDIVERT_DATA_SOCKET;
+
+typedef struct
+{
+ INT64 Timestamp;
+ UINT32 ProcessId;
+ WINDIVERT_LAYER Layer;
+ UINT64 Flags;
+ INT16 Priority;
+} WINDIVERT_DATA_REFLECT, *PWINDIVERT_DATA_REFLECT;
+
+typedef struct
+{
+ INT64 Timestamp;
+ UINT64 Layer:8;
+ UINT64 Event:8;
+ UINT64 Outbound:1;
+ UINT64 Loopback:1;
+ UINT64 Impostor:1;
+ UINT64 IPv6:1;
+ UINT64 PseudoIPChecksum:1;
+ UINT64 PseudoTCPChecksum:1;
+ UINT64 PseudoUDPChecksum:1;
+ union
+ {
+ WINDIVERT_DATA_NETWORK Network;
+ WINDIVERT_DATA_FLOW Flow;
+ WINDIVERT_DATA_SOCKET Socket;
+ WINDIVERT_DATA_REFLECT Reflect;
+ };
} WINDIVERT_ADDRESS, *PWINDIVERT_ADDRESS;
|
HANDLE WinDivertOpen( @@ -572,7 +794,7 @@ Note that only one of WINDIVERT_FLAG_SNIFF or -
|