maybe I should send it here.
---------- Forwarded message ----------
From:
Wenfei Wu <wenfeiwu@xxxxxxxxxxx>
Date: Tue, Jan 29, 2013 at 3:39 PM
Subject: How does wireshark filter packets
To:
wireshark-dev@xxxxxxxxxxxxxHi, all,
I want to know how wireshark use the filter _expression_ to filter packets. Does it parse the packet first, and then use the filter _expression_ to check? If so, is there some intermediate data structure to store the filter _expression_? What is the algorithm?
Is there some materials about this?
Regards,
Wenfei Wu