diff --git a/doc/windivert.html b/doc/windivert.html index ca9dec3..7190709 100644 --- a/doc/windivert.html +++ b/doc/windivert.html @@ -19,16 +19,17 @@
-The WINDIVERT_LAYER_NETWORK (and
-WINDIVERT_LAYER_NETWORK_FORWARD) layers
-allow the user application to capture/block/inject network packets passing
-to/from (and through) the local machine.
-These represent the traditional
-WinDivert layers.
-Only a single event is supported:
-
WINDIVERT_EVENT_NETWORK_PACKET: A new network packet was
- intercepted.WINDIVERT_LAYER_NETWORK and
+WINDIVERT_LAYER_NETWORK_FORWARD
+layers allow the user application to capture/block/inject network packets
+passing to/from (and through) the local machine.
Due to technical limitations, process ID information is not available
at these layers.
+
The WINDIVERT_LAYER_FLOW layer captures information about
network flow establishment/deletion events.
Here, a flow represents either (1) a
TCP connection, or (2) an implicit flow
created by the first
sent/received packet for non-TCP traffic, e.g., UDP.
-The WINDIVERT_LAYER_FLOW layer supports two events:
-
WINDIVERT_EVENT_FLOW_ESTABLISHED: A new flow is created.WINDIVERT_EVENT_FLOW_DELETED: An old flow is deleted.
Old flows are deleted when the corresponding connection is closed (for TCP),
-or on a timeout (non-TCP).
-Flow events can be captured, but never blocked or injected.
-Process ID information is available at this layer.
+or based on an activity timeout (non-TCP).
+Flow-related events can be captured, but not blocked nor injected.
+Process ID information is also available at this layer.
Due to technical limitations, the
-WINDIVERT_LAYER_FLOW layer cannot capture events that
-occurred before the WinDivert handle was opened.
+WINDIVERT_LAYER_FLOW layer cannot capture flow events that
+occurred before the handle was opened.
-The WINDIVERT_LAYER_SOCKET layer captures/blocks events that
-correspond to socket operations, such as:
-
WINDIVERT_EVENT_SOCKET_BIND: A bind() operation.WINDIVERT_EVENT_SOCKET_UNBIND: A previous binding is
- removed.WINDIVERT_EVENT_SOCKET_CONNECT: A connect()
- operation.WINDIVERT_EVENT_SOCKET_DISCONNECT: A previous connection
- is terminated.WINDIVERT_EVENT_SOCKET_LISTEN: A listen() operation.WINDIVERT_EVENT_SOCKET_ACCEPT: An accept()
- operation.
-Socket events, except for UNBIND/DISCONNECT,
-can be blocked, and no socket event can be injected.
-Process ID information is available at this layer.
-Due to technical limitations, the
-WINDIVERT_LAYER_SOCKET layer cannot capture events that
-occurred before the WinDivert handle was opened.
+The WINDIVERT_LAYER_SOCKET layer can capture or block events
+corresponding to socket operations, such as bind(),
+connect(), listen(), etc., or the termination
+of socket operations, such as a TCP socket disconnection.
+Unlike the flow layer, most socket-related events can be blocked.
+However, it is not possible to inject new or modified socket events.
+Process ID information (of the process responsible for the socket operation)
+is available at this layer.
+Due to technical limitations, this layer cannot capture events that
+occurred before the handle was opened.
-Finally, the WINDIVERT_LAYER_REFLECT layer captures events related
-to WinDivert itself, such as:
-
WINDIVERT_EVENT_REFLECT_OPEN: A new WinDivert handle was
- opened.WINDIVERT_EVENT_REFLECT_CLOSE: An old WinDivert handle was
- closed.
-These events can be captured, but not injected nor blocked.
-Process ID information is available at this layer,
-meaning that it is possible to determine which (if any) process is using
-WinDivert.
-The layer also returns an object
representation of the filter string
-used to open the handle.
+Finally, the WINDIVERT_LAYER_REFLECT layer can capture events
+relating to WinDivert itself, such as when another process opens a
+new WinDivert handle, or closes an old WinDivert handle.
+WinDivert events can be captured but not injected nor blocked.
+Process ID information (of the process responsible for opening the
+WinDivert handle) is available at this layer.
+This layer also returns data in the form of an object
representation
+of the filter string used to open the handle.
The object representation can be converted back into a human-readable
filter string using the
WinDivertHelperFormatFilter()
function.
-The WINDIVERT_LAYER_REFLECT layer can also capture events that
-occurred before the handle was opened.
+This layer can also capture events that occurred before the handle was opened.
+This layer cannot capture events related to other
+WINDIVERT_LAYER_REFLECT-layer handles.
+
+typedef enum
+{
+ WINDIVERT_EVENT_NETWORK_PACKET,
+ WINDIVERT_EVENT_FLOW_ESTABLISHED,
+ WINDIVERT_EVENT_FLOW_DELETED,
+ WINDIVERT_EVENT_SOCKET_BIND,
+ WINDIVERT_EVENT_SOCKET_UNBIND,
+ WINDIVERT_EVENT_SOCKET_CONNECT,
+ WINDIVERT_EVENT_SOCKET_DISCONNECT,
+ WINDIVERT_EVENT_SOCKET_LISTEN,
+ WINDIVERT_EVENT_SOCKET_ACCEPT,
+ WINDIVERT_EVENT_REFLECT_OPEN,
+ WINDIVERT_EVENT_REFLECT_CLOSE,
+} WINDIVERT_EVENT, *PWINDIVERT_EVENT;
+
+ |
+Each layer supports one or more events summarized below: +
+
+WINDIVERT_LAYER_NETWORK and
+WINDIVERT_LAYER_NETWORK_FORWARD:
+Only a single event is supported:
+
| Event | +Description | +
|---|---|
+WINDIVERT_EVENT_NETWORK_PACKET
+ |
++A new network packet. + | +
+WINDIVERT_LAYER_FLOW:
+Two events are supported:
+
| Event | +Description | +
|---|---|
+WINDIVERT_EVENT_FLOW_ESTABLISHED
+ |
++A new flow is created. + | +
+WINDIVERT_EVENT_FLOW_DELETED
+ |
++An old flow is deleted. + | +
+WINDIVERT_LAYER_SOCKET:
+The following events are supported:
+
| Event | +Description | +
|---|---|
+WINDIVERT_EVENT_SOCKET_BIND
+ |
+
+A bind() operation.
+ |
+
+WINDIVERT_EVENT_SOCKET_UNBIND
+ |
++A previous binding is removed. +This event cannot be blocked. + | +
+WINDIVERT_EVENT_SOCKET_CONNECT
+ |
+
+A connect() operation.
+ |
+
+WINDIVERT_EVENT_SOCKET_DISCONNECT
+ |
++A previous connection is terminated. +This event cannot be blocked. + | +
+WINDIVERT_EVENT_SOCKET_LISTEN
+ |
+
+A listen() operation.
+ |
+
+WINDIVERT_EVENT_SOCKET_ACCEPT
+ |
+
+An accept() operation.
+ |
+
+WINDIVERT_LAYER_REFLECT:
+Two events are supported:
+
| Event | +Description | +
|---|---|
+WINDIVERT_EVENT_REFLECT_OPEN
+ |
++A new WinDivert handle was opened. + | +
+WINDIVERT_EVENT_REFLECT_CLOSE
+ |
++An old WinDivert handle was closed. + | +
typedef struct @@ -572,7 +712,7 @@ The
|