<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Sniffer (protocol analyzer)</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Sniffer_(protocol_analyzer)"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Sniffer_protocol_analyzer rootpage-Sniffer_protocol_analyzer skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Sniffer (protocol analyzer)</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */
.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}
/* end https://en.wikipedia.org/ */
</style><table class="infobox vevent"><tbody><tr><th colspan="2" class="infobox-above summary">Sniffer</th></tr><tr><td colspan="2" class="infobox-image logo"><span typeof="mw:File"></span></td></tr><tr><td colspan="2" class="infobox-image logo"><span typeof="mw:File"></span></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Original author(s)</a></th><td class="infobox-data"><style data-mw-deduplicate="TemplateStyles:r1126788409">
/* start https://en.wikipedia.org/ */
.mw-parser-output .plainlist ol,.mw-parser-output .plainlist ul{line-height:inherit;list-style:none;margin:0;padding:0}.mw-parser-output .plainlist ol li,.mw-parser-output .plainlist ul li{margin-bottom:0}
/* end https://en.wikipedia.org/ */
</style><div class="plainlist"><ul><li><a href="Harry_Saal" title="Harry Saal">Harry Saal</a></li><li><a href="Len_Shustek" title="Len Shustek">Len Shustek</a></li></ul></div></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Developer(s)</a></th><td class="infobox-data"><a href="Network_General" title="Network General">Network General</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Initial release</th><td class="infobox-data">December 1986</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Written in</th><td class="infobox-data">C, 8086 assembler</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Operating_system" title="Operating system">Operating system</a></th><td class="infobox-data">MS-DOS</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_categories#Categorization_approaches" title="Software categories">Type</a></th><td class="infobox-data">protocol analyzer</td></tr></tbody></table>
<p><b>The Sniffer</b><sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> was a computer <a href="Packet_analyzer" title="Packet analyzer">network packet and protocol analyzer</a> developed and first sold in 1986 by <a href="Network_General_Corporation" class="mw-redirect" title="Network General Corporation">Network General Corporation</a><sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> of Mountain View, CA. By 1994 the Sniffer had become the market leader<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> in high-end protocol analyzers. According to SEC 10-K filings<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> and corporate annual reports,<sup id="cite_ref-:0_7-0" class="reference"><a href="#cite_note-:0-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> between 1986 and March 1997 about $933M worth of Sniffers and related products and services had been sold as tools for network managers and developers.
</p><p>The Sniffer was the antecedent of several generations of network protocol analyzers, of which the current most popular is <a href="Wireshark" title="Wireshark">Wireshark</a>.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Background">Background </h2></div>
<p>The Sniffer was the first product of <a href="Network_General_Corporation" class="mw-redirect" title="Network General Corporation">Network General Corporation</a>, founded on May 13, 1986<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> by <a href="Harry_Saal" title="Harry Saal">Harry Saal</a> and <a href="Len_Shustek" title="Len Shustek">Len Shustek</a> to develop and market network protocol analyzers. The inspiration was an internal test tool that had been developed within <a href="Nestar_Systems" title="Nestar Systems">Nestar Systems</a>,<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> a personal computer networking company founded in October 1978 by Saal and Shustek along with Jim Hinds and Nick Fortis. In 1982 engineers John Rowlands and Chris Reed at Nestar’s UK subsidiary Zynar Ltd developed an <a href="ARCNET" title="ARCNET">ARCNET</a> promiscuous packet receiver and analyzer called TART (“Transmit and Receive Totaliser”) for use as an internal engineering test tool. It used custom hardware, and software for an IBM PC written in a combination of BASIC and 8086 assembly code. When Nestar was acquired by Digital Switch Corporation (now DSC Communications) of Plano, Texas in 1986,<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> Saal and Shustek received the rights to TART.
</p><p>At Network General, Saal and Shustek initially sold TART as the “R-4903 ARCNET Line Analyzer (‘The Sniffer’)”.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> They then reengineered TART for IBM’s <a href="Token_Ring" title="Token Ring">Token Ring</a> network hardware, created a different user interface with software written in C, and began selling it as The Sniffer™ in December 1986.<sup id="cite_ref-:2_13-0" class="reference"><a href="#cite_note-:2-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> The company had four employees at the end of that year.
</p><p>In April 1987 the company released an Ethernet version of the Sniffer,<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> and in October, versions for ARCNET, <a href="StarLAN" title="StarLAN">StarLAN</a>, and <a href="IBM_PC_Network" title="IBM PC Network">IBM PC Network</a> Broadband. Protocol interpreters were written for about 100 network protocols at various levels of the <a href="Protocol_stack" title="Protocol stack">protocol stack</a>, and customers were given the ability to write their own interpreters. The product line gradually expanded to include the Distributed Sniffer System<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> for multiple remote network segments, the Expert Sniffer<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> for advanced problem diagnosis, and the Watchdog<sup id="cite_ref-:1_18-0" class="reference"><a href="#cite_note-:1-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup> for simple network monitoring.
</p>
<div class="mw-heading mw-heading2"><h2 id="Development">Development</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Nestar_ARCNET_Sniffer">Nestar ARCNET Sniffer </h3></div>
<p>The ARCNET Sniffer developed as an internal test tool by Zynar used the IBM PC ARCNET Network Interface Card developed by Nestar for the PLAN networking systems. That board used the COM9026 integrated ARCNET controller from <a href="Standard_Microsystems_Corporation" class="mw-redirect" title="Standard Microsystems Corporation">Standard Microsystems Corporation</a>, which had been developed in collaboration with Datapoint.
</p><p>There was no promiscuous mode in the SMC chip that would allow all packets to be received regardless of the destination address. So to create the Sniffer, a daughterboard<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> was developed that intercepted the receive data line to the chip and manipulated the data so that every packet looked like a broadcast and was received by the chip.
</p>
<p>Since the ability to receive all packets was viewed as a violation of network privacy, the circuitry implementing it was kept secret, and the daughterboard was potted in black epoxy to discourage reverse-engineering.
</p><p>The source code of the original TART/Sniffer BASIC and assembler program is available on GitHub.<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Network_General_Sniffer">Network General Sniffer </h3></div>
<p>The Sniffer was a <a href="Promiscuous_mode" title="Promiscuous mode">promiscuous mode</a> packet receiver, which means it received a copy of all network packets without regard to what computer they were addressed to. The packets were filtered, analyzed using what is now sometimes called <a href="Deep_packet_inspection" title="Deep packet inspection">deep packet inspection</a>, and stored for later examination.
</p><p>The Sniffer was implemented above Microsoft’s <a href="MS-DOS" title="MS-DOS">MS-DOS</a> operating system, and used a 40 line 80-character text-only display. The first version, the PA-400 protocol analyzer for Token-Ring networks,<sup id="cite_ref-:3_21-0" class="reference"><a href="#cite_note-:3-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup> was released on a <a href="Compaq_Portable_II" title="Compaq Portable II">Compaq Portable II</a> “luggable” computer that had an Intel 80286 processor, 640 KB of RAM, a 20 MB internal hard disk, a 5 ¼” floppy disk drive, and a 9” monochrome CRT screen. The retail price of the Sniffer in unit quantities was $19,995.<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup>
</p>
<p>The two major modes of operation<sup id="cite_ref-:2_13-1" class="reference"><a href="#cite_note-:2-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> were:
</p>
<ul><li>“capture”, in which
<ul><li>packets are captured, stored, counted, and summarized</li>
<li>filters control which packets are captured</li>
<li>triggers control when capture should stop, perhaps because a sought-after network error condition had occurred</li></ul></li>
<li>“display”, in which
<ul><li>packets are analyzed and interpreted</li>
<li>filters control which packets are displayed</li>
<li>options control which aspects of the packets are displayed</li></ul></li></ul>
<p>Navigation of the extensive menu system on the character-mode display was through a variation of <a href="Miller_columns" title="Miller columns">Miller columns</a> that were originally created by <a href="Mark_S._Miller" title="Mark S. Miller">Mark S. Miller</a> at <a href="Datapoint_Corporation" class="mw-redirect" title="Datapoint Corporation">Datapoint Corporation</a> for their file browser. As the Sniffer manual described, “The screen shows you three panels, arranged from left to right. Immediately to the left of your current (highlighted) position is the node you just came from. Above and below you in the center panel are alternative nodes that are also reachable from the node to your left… To your right are nodes reachable from the node you're now on.”
</p>
<p>Pressing F10 initiated capture and a real-time display of activity.<sup id="cite_ref-:3_21-1" class="reference"><a href="#cite_note-:3-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
</p>
<p>When capture ended, packets were analyzed and displayed in one or more of the now-standard three synchronized vertical windows: multiple packet summary, single packet decoded detail, and raw numerical packet data. Highlighting linked the selected items in each window.
</p><p>In the multiple-packet summary, the default display was of information at the highest level of the protocol stack present in that packet. Other displays could be requested using the “display options” menu.
</p><p>The translation of data at a particular level of the network protocol stack into user-friendly text was the job of a “protocol interpreter”, or PI. Network General provided over 100 PI’s<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup> for commonly used protocols of the day:
</p>
<style data-mw-deduplicate="TemplateStyles:r1184024115">
/* start https://en.wikipedia.org/ */
.mw-parser-output .div-col{margin-top:0.3em;column-width:30em}.mw-parser-output .div-col-small{font-size:90%}.mw-parser-output .div-col-rules{column-rule:1px solid #aaa}.mw-parser-output .div-col dl,.mw-parser-output .div-col ol,.mw-parser-output .div-col ul{margin-top:0}.mw-parser-output .div-col li,.mw-parser-output .div-col dd{page-break-inside:avoid;break-inside:avoid-column}
/* end https://en.wikipedia.org/ */
</style><div class="div-col" style="column-width: 15em;">
<ul><li>3COM 3+</li>
<li>AppleTalk ADSP</li>
<li>AppleTalk AFP</li>
<li>AppleTalk ARP</li>
<li>AppleTalk ASP</li>
<li>AppleTalk ATP</li>
<li>AppleTalk DDP</li>
<li>AppleTalk ECHO</li>
<li>AppleTalk KSP</li>
<li>AppleTalk LAP</li>
<li>AppleTalk NBP</li>
<li>AppleTalk PAP</li>
<li>AppleTalk RTMP</li>
<li>AppleTalk ZIP</li>
<li>ARP</li>
<li>AT&T</li>
<li>Banyan VINES AFRP</li>
<li>Banyan VINES Echo</li>
<li>Banyan VINES File Svc</li>
<li>Banyan VINES FRP</li>
<li>Banyan VINES FTP</li>
<li>Banyan VINES IP</li>
<li>Banyan VINES LLC</li>
<li>Banyan VINES Loopback</li>
<li>Banyan VINES Matchmaker</li>
<li>Banyan VINES Ntwk Mgr</li>
<li>Banyan VINES SPP</li>
<li>Banyan VINES StreetTalk</li>
<li>Banyan VINES Svr Svc</li>
<li>Banyan VINES Talk</li>
<li>BOOTP</li>
<li>Bridge bridge mgmt</li>
<li>Bridge CS-1</li>
<li>Bridge terminal srvr</li>
<li>Chaosnet</li>
<li>ComDesign</li>
<li>Cronus direct</li>
<li>Cronus VLN</li>
<li>Datapoint DLL</li>
<li>Datapoint RCL</li>
<li>Datapoint RIO</li>
<li>Datapoint RMS</li>
<li>DEC 911</li>
<li>DEC bridge mgmt</li>
<li>DEC LAN monitor</li>
<li>DEC LAST</li>
<li>DEC LAVC</li>
<li>DEC NetBIOS</li>
<li>DECNET CTERM</li>
<li>DECNET DAP</li>
<li>DECNET DRP</li>
<li>DECNET FOUND</li>
<li>DECNET LAT</li>
<li>DECNET LAVC</li>
<li>DECNET MOP</li>
<li>DECNET NICE</li>
<li>DECNET NSP</li>
<li>DECNET SCP</li>
<li>DNS</li>
<li>ECMA internet</li>
<li>EGP</li>
<li>Excelan</li>
<li>FTP</li>
<li>GGP</li>
<li>IBM SMB</li>
<li>IBM SNA</li>
<li>ICMP</li>
<li>IONET VCS</li>
<li>IONET VCS CMND</li>
<li>IONET VCS DATA</li>
<li>IONET VCS TRANS</li>
<li>IP</li>
<li>ISO ACSE</li>
<li>ISO ASN.1</li>
<li>ISO CMIP</li>
<li>ISO Network</li>
<li>ISO PPP</li>
<li>ISO ROSE</li>
<li>ISO Session</li>
<li>ISO SMTP</li>
<li>ISO Transport</li>
<li>LOOP</li>
<li>Loopback</li>
<li>Micom test</li>
<li>NBS internet</li>
<li>Nestar ARCnet</li>
<li>Nestar PlanSeries</li>
<li>NetBIOS</li>
<li>NetBIOS TCP</li>
<li>Novell Netware</li>
<li>PUP address translation</li>
<li>RPL</li>
<li>RUnix</li>
<li>SMTP</li>
<li>SNAP</li>
<li>Sun MOUNT</li>
<li>Sun NFS</li>
<li>Sun PMAP</li>
<li>Sun RPC</li>
<li>Sun RSTAT</li>
<li>Sun YP</li>
<li>Symbolics private</li>
<li>TCP</li>
<li>Telnet</li>
<li>TFTP</li>
<li>TRING DLC</li>
<li>TRING LLC</li>
<li>TRING MAC</li>
<li>TRING RI</li>
<li>U-B</li>
<li>Vitalink bridge mgmt</li>
<li>X.25</li>
<li>X.25 level 3</li>
<li>X.75 internet</li>
<li>Xerox BOOTP</li>
<li>Xerox EGP</li>
<li>Xerox GGP</li>
<li>Xerox ND</li>
<li>Xerox PUP</li>
<li>Xerox PUP ARP</li>
<li>Xerox RIP</li>
<li>Xerox TFTP</li>
<li>Xerox XNS</li>
<li>Xyplex</li></ul></div>
<p>Decoding higher protocol levels often required the interpreter to maintain state information about connections so that subsequent packets could be property interpreted. That was implemented with a combination of locally cached data within the protocol interpreter, and the ability to look back at earlier packets stored in the capture buffer.
</p><p>Sniffer customers could write their own protocol interpreters to decode new or rare protocols not supported by Network General. Interpreters were written in C and linked with the rest of the Sniffer modules to create a new executable program. The procedure for creating new PIs was documented in April 1987 as part of Sniffer version 1.20.<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup>
</p><p>In addition to supporting many network protocols, there were versions of the Sniffer that collected data from the major local area networks in use in the 1980s and early 1990s:
</p>
<ul><li>IBM Token-Ring</li>
<li><a href="Token_Bus" class="mw-redirect" title="Token Bus">Token Bus</a></li>
<li>Ethernet (thick, thin, twisted pair)</li>
<li>Datapoint ARCnet</li>
<li>Starlan</li>
<li><a href="AppleTalk" title="AppleTalk">AppleTalk</a></li>
<li>Corvus Omninet</li>
<li><a href="FDDI" class="mw-redirect" title="FDDI">FDDI</a></li>
<li><a href="ISDN" title="ISDN">ISDN</a></li>
<li><a href="Frame_Relay" title="Frame Relay">Frame Relay</a></li>
<li><a href="Synchronous_Data_Link_Control" title="Synchronous Data Link Control">Synchronous Data Link Control</a> (SDLC)</li>
<li><a href="Asynchronous_Transfer_Mode" title="Asynchronous Transfer Mode">Asynchronous Transfer Mode</a> (ATM)</li>
<li><a href="X.25" title="X.25">X.25</a></li>
<li><a href="IBM_PC_Network" title="IBM PC Network">IBM PC Network</a> (Sytek)</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Competitors">Competitors</h2></div>
<p>Even in the early years, the Sniffer had competition,<sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> at least for some aspects of the product. Several were, like the Sniffer, ready-to-use packaged instruments:
</p>
<ul><li><a href="Excelan" title="Excelan">Excelan</a>'s 1984 Nutcracker,<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup> and its 1986 LANalyzer<sup id="cite_ref-27" class="reference"><a href="#cite_note-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup></li>
<li>Communications Machinery Corporation's DRN-1700 LanScan Ethernet Monitor</li>
<li>Hewlett-Packard's HP-4972A LAN Protocol Analyzer<sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup></li>
<li>Digital Equipment Corporation's LAN Traffic Monitor<sup id="cite_ref-29" class="reference"><a href="#cite_note-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup></li>
<li>Tektronix's TMA802 Media Analyzer<sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup></li></ul>
<p>There were also several software-only packet monitors and decoders, often running on Unix, and often with only a command-line user interface:
</p>
<ul><li><a href="Tcpdump" title="Tcpdump">tcpdump</a>, using the <a href="Berkeley_Packet_Filter" title="Berkeley Packet Filter">Berkeley Packet Filter</a><sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup> and other capture mechanisms provided by the operating system</li>
<li>LANWatch,<sup id="cite_ref-32" class="reference"><a href="#cite_note-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup> originally from <a href="FTP_Software" title="FTP Software">FTP Software</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Comparison_of_packet_analyzers" title="Comparison of packet analyzers">Comparison of packet analyzers</a></li>
<li><a href="Wireshark" title="Wireshark">Wireshark</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFJoch2001" class="citation web cs1">Joch, Alan (2001-07-23). <a rel="nofollow" class="external text" href="https://www.computerworld.com/article/2583125/network-sniffers.html">"Network Sniffers"</a>. <i>Computerworld</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-02-16</span></span>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.computerhistory.org/tdih/may/13/">"May 13: Network General Corporation Founded | This Day in History | Computer History Museum"</a>. <i>www.computerhistory.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-02-16</span></span>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite id="CITEREFMusthaler1994" class="citation magazine cs1">Musthaler, Linda (1994-02-21). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=hhAEAAAAMBAJ&pg=PA35">"Merger will hone net analysis focus"</a>. <i>Network World</i>. Vol. 11, no. 8. <a href="International_Data_Group" title="International Data Group">International Data Group</a>. p. 35.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.sec.gov/Archives/edgar/data/844643/0000912057-95-004918.txt">"Network General Corporation FY95 10-K"</a>. <i>SEC Edgar database</i>. June 28, 1995.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.sec.gov/Archives/edgar/data/844643/0000912057-96-013315.txt">"Network General Corporation FY96 10-K"</a>. <i>SEC Edgar database</i>. July 25, 1996.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.sec.gov/Archives/edgar/data/844643/0000912057-97-022239.txt">"Network General Corporation FY97 10-K"</a>. <i>SEC Edgar database</i>. June 27, 1997.</cite></span>
</li>
<li id="cite_note-:0-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-:0_7-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://archive.org/details/1993-network-general-annual-report">"Network General Corp. annual reports 1989-1993, 1995, 1997"</a> – via Internet Archive.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFPetrosky1987" class="citation magazine cs1">Petrosky, Mary (1987-06-22). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=aR0EAAAAMBAJ&pg=PA15">"Network General smells success with Sniffer"</a>. <i>Network World</i>. Vol. 4, no. 25. <a href="International_Data_Group" title="International Data Group">International Data Group</a>. p. 15.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite class="citation cs2"><a rel="nofollow" class="external text" href="https://www.youtube.com/watch?v=EvenCsv9d4s"><i>"Presenting Network General Corporation", July 1992</i></a>, 17 November 2021<span class="reference-accessdate">, retrieved <span class="nowrap">2021-11-17</span></span></cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite id="CITEREFPrins1979" class="citation journal cs1">Prins, G.A. (November–December 1979). <span class="id-lock-subscription" title="Paid subscription required"><a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/5198054">"Distributing computing at the personal level"</a></span>. <i>Electronics and Power</i>. <b>25</b> (11): 765. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1049%2Fep.1979.0422">10.1049/ep.1979.0422</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0013-5127">0013-5127</a>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite id="CITEREFFlynn1986" class="citation magazine cs1">Flynn, Laurie (1986-11-24). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=hTwEAAAAMBAJ&pg=PA25">"Nestar Says Firm's Acquisition To Improve LAN and PBX Links"</a>. <i>InfoWorld</i>. Vol. 8, no. 48. InfoWorld Media Group, Inc. p. 25.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite class="citation book cs1"><a rel="nofollow" class="external text" href="http://archive.org/details/network-general-r-4903-arcnet-line-analyzer-manual-sep-1986"><i>Network General R 4903 ARCNET Line Analyzer Manual Sep 1986</i></a>. Network General. 1986-09-25.</cite></span>
</li>
<li id="cite_note-:2-13"><span class="mw-cite-backlink">^ <a href="#cite_ref-:2_13-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:2_13-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation book cs1"><a rel="nofollow" class="external text" href="http://archive.org/details/network-general-token-ring-sniffer-v-1.0-dec-1986"><i>Network General Token Ring Sniffer V 1.0 Dec 1986</i></a>. Network General Corporation. December 1986.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite class="citation book cs1"><a rel="nofollow" class="external text" href="http://archive.org/details/network-general-ethernet-sniffer-introduction-apr-1987"><i>Network General Ethernet Sniffer Introduction Apr 1987</i></a>. Network General. 1987-04-01.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite class="citation book cs1"><a rel="nofollow" class="external text" href="http://archive.org/details/network-general-ethernet-sniffer-jun-1988"><i>Network General Ethernet Sniffer Jun 1988</i></a>. Network General. 1988-06-01.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><cite id="CITEREFSmalley1991" class="citation magazine cs1">Smalley, Eric (1991-04-01). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=bhAEAAAAMBAJ&pg=PA4">"Sniffer Gains Distributed Management Capabilities"</a>. <i>Network World</i>. Vol. 8, no. 13. <a href="International_Data_Group" title="International Data Group">International Data Group</a>. p. 4.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite id="CITEREFBusse1992" class="citation magazine cs1">Busse, Torsten (1992-09-28). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=klEEAAAAMBAJ&pg=PA45">"Expert Sniffer to Diagnose WANs"</a>. <i>InfoWorld</i>. Vol. 14, no. 39. InfoWorld Media Group, Inc. p. 45.</cite></span>
</li>
<li id="cite_note-:1-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-:1_18-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFTaft1990" class="citation magazine cs1">Taft, Peter (1990-08-27). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=7zsEAAAAMBAJ&pg=PT55">"The Watchdog Sniffs Out LAN Traffic Statistics"</a>. <i>InfoWorld</i>. Vol. 12, no. 35. InfoWorld Media Group, Inc. p. 54.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite class="citation book cs1"><a rel="nofollow" class="external text" href="http://archive.org/details/nestar-arcnet-sniffer-internal-descriptions"><i>Nestar ARCNET Sniffer Internal Descriptions</i></a>. Nestar Systems. 1982–1984.</cite></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/LenShustek/NestarSystems">NestarSystems/ARCNET_Sniffer</a> on <a href="GitHub" title="GitHub">GitHub</a></span>
</li>
<li id="cite_note-:3-21"><span class="mw-cite-backlink">^ <a href="#cite_ref-:3_21-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:3_21-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://archive.org/details/1986-12-network-general-large-brochure">"1986 12 Network General Large Brochure : Free Download, Borrow, and Streaming"</a>. <i>Internet Archive</i>. December 1986<span class="reference-accessdate">. Retrieved <span class="nowrap">2021-06-03</span></span>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://archive.org/details/1987-03-16-network-general-price-list-end-user">"1987 03 16 Network General Price List End User : Free Download, Borrow, and Streaming"</a>. <i>Internet Archive</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-06-03</span></span>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://archive.org/details/1991-04-the-network-is-your-business">"1991 04 The Network Is Your Business : Network General Corp. : Free Download, Borrow, and Streaming"</a>. <i>Internet Archive</i>. April 1991<span class="reference-accessdate">. Retrieved <span class="nowrap">2021-06-04</span></span>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite class="citation book cs1"><a rel="nofollow" class="external text" href="http://archive.org/details/network-general-token-ring-sniffer-v-1.20-addendum-apr-1987"><i>Network General Token Ring Sniffer V 1.20 Addendum Apr 1987</i></a>. Network General. 1987-04-01.</cite></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><cite id="CITEREFGlass1989" class="citation magazine cs1">Glass, Brett (1989-02-06). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=OzoEAAAAMBAJ&pg=PT63">"LAN Analyzers: Powerful Tools Useful For Serious Network Analysis"</a>. <i>InfoWorld</i>. Vol. 11, no. 6. InfoWorld Media Group, Inc. p. S14.</cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><cite id="CITEREFSatyanarayanan1984" class="citation web cs1">Satyanarayanan, M (September 22, 1984). <a rel="nofollow" class="external text" href="http://reports-archive.adm.cs.cmu.edu/anon/itc/CMU-ITC-034.pdf">"The Excelan Nutcracker: An Evaluation"</a> <span class="cs1-format">(PDF)</span>.</cite></span>
</li>
<li id="cite_note-27"><span class="mw-cite-backlink"><b><a href="#cite_ref-27">^</a></b></span> <span class="reference-text"><cite class="citation book cs1"><a rel="nofollow" class="external text" href="http://www.bitsavers.org/pdf/excelan/LANalyzer/EX5000E_LANalyzer_User_Manual_Feb86.pdf"><i>LANalyzer EX5000E Ethernet Network Analyzer</i></a> <span class="cs1-format">(PDF)</span>. Excelan. 1986.</cite></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite id="CITEREFHP_Computer_Museum" class="citation web cs1">HP Computer Museum. <a rel="nofollow" class="external text" href="http://www.hpmuseum.net/display_item.php?hw=938">"4972A Protocol Analyzer"</a>. <i>www.hpmuseum.net</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-02-18</span></span>.</cite></span>
</li>
<li id="cite_note-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-29">^</a></b></span> <span class="reference-text"><cite id="CITEREFPabrai" class="citation web cs1">Pabrai, Uday. <a rel="nofollow" class="external text" href="https://lss.fnal.gov/archive/test-tm/2000/fermilab-tm-2578-cd.pdf">"Understanding and Using Computer Networks"</a> <span class="cs1-format">(PDF)</span>. p. 3-26.</cite></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://worldradiohistory.com/hd2/IDX-Service-&-Sales-IDX/Archive-PF-IDX/IDX/80s/EST-1987-12-OCR-Page-0021.pdf">"Quick and Accurate LAN Measurements"</a> <span class="cs1-format">(PDF)</span>.</cite></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text"><cite id="CITEREFMcCann1992" class="citation web cs1">McCann, Steven (December 19, 1992). <a rel="nofollow" class="external text" href="https://www.tcpdump.org/papers/bpf-usenix93.pdf">"The BSD Packet Filter: A New Architecture for User-level Packet Capture"</a> <span class="cs1-format">(PDF)</span>.</cite></span>
</li>
<li id="cite_note-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-32">^</a></b></span> <span class="reference-text"><cite class="citation magazine cs1"><a rel="nofollow" class="external text" href="https://books.google.com/books?id=QTsEAAAAMBAJ&pg=PA85">"LANWatch Version 3.0"</a>. <i>InfoWorld</i>. Vol. 15, no. 19. InfoWorld Media Group, Inc. 1993-05-10. p. 85.</cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li>"The Ancient History of Computers and Network Sniffers" (Sharkfest 2021 keynote talk) - <cite class="citation cs2"><a rel="nofollow" class="external text" href="https://www.youtube.com/watch?v=x0hCRSfFN78"><i>SF16 - Len Shustek Keynote</i></a>, 25 June 2016<span class="reference-accessdate">, retrieved <span class="nowrap">2021-08-17</span></span></cite></li>
<li><cite id="CITEREFHaugdahl1988" class="citation conference cs1">Haugdahl, J. S. (October 1988). <span class="id-lock-subscription" title="Paid subscription required"><a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/10251">"Benchmarking LAN protocol analyzers"</a></span>. <i>Proceedings [1988] 13th Conference on Local Computer Networks</i>. pp. <span class="nowrap">375–</span>384. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FLCN.1988.10251">10.1109/LCN.1988.10251</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>0-8186-0891-9</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:336848">336848</a>.</cite></li>
<li><cite id="CITEREFChartoff1987" class="citation magazine cs1">Chartoff, Marvin (1987-12-14). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=mRMEAAAAMBAJ&pg=PA37">"LAN management: What's the right tool for the job?"</a>. <i>Network World</i>. Vol. 4, no. 50. <a href="International_Data_Group" title="International Data Group">International Data Group</a>. p. 37.</cite></li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-06-22" href="https://en.wikipedia.org/wiki/?title=Sniffer_(protocol_analyzer)&oldid=1296772258">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>