Protocol Dissector
Definition
A software component in a packet analyser that recognises a specific protocol and parses its header fields into named, readable values. Wireshark includes hundreds of built-in dissectors; analysts can also write custom dissectors in Lua for proprietary or custom protocols.
- Function
- Parses protocol headers into readable named fields
- Common tool
- Wireshark, hundreds of built-in dissectors
- Custom option
- Lua scripting for proprietary protocols
- Use case
- Traffic analysis and protocol dissection
Common questions
Why would an investigator need to write a custom dissector?+
Proprietary or vendor-specific protocols, such as an industrial control system's command format, have no built-in Wireshark dissector, so without a custom Lua dissector the analyst is left reading raw hex bytes instead of labeled fields.
Can a dissector misinterpret traffic and mislead an analysis?+
Yes. A dissector applies a fixed interpretation of byte offsets, so malformed or intentionally crafted packets can be mis-parsed and displayed with misleading field values, which is why raw hex should be checked when a dissected result looks anomalous.
Related terms
- Artefact Carving
- Extracting embedded content from raw data by locating known file signatures (magic bytes) at byte boundaries. In PCAP analysis, this means reassembling...
- Beaconing
- Periodic outbound connections from a compromised host to a command-and-control server, typically at regular intervals. The regularity of the interval, measured in...
- Display Filter
- A Wireshark filter expression applied to an already-captured PCAP file to show only packets matching specified criteria. Display filters do not delete...
- PCAP
- Packet capture file. The standard format for storing captured network frames, originally defined by the libpcap library. Each record contains the raw...
- Stream Reassembly
- The process of collecting all the TCP segments belonging to a single connection and reordering them by sequence number to reconstruct the...