Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] Improving TCAP session matching

From: Luke Mewburn <luke@xxxxxxxxxxx>
Date: Sun, 4 Jan 2015 13:11:20 +1100
On Sat, Jan 03, 2015 at 04:49:06PM -0800, Guy Harris wrote:
  | 
  | On Jan 3, 2015, at 4:32 PM, Luke Mewburn <luke@xxxxxxxxxxx> wrote:
  | 
  | > I suspect we need special-case handling in find_conversation() (etc)
  | > for PT_TCAP, including possibly a separate hashtable or keeping
  | > the TCAP BEGIN in the conversation_hashtable_no_addr2_or_port2 in
  | > parallel to the entry in conversation_hashtable_exact.
  | 
  | I suspect what we need is to separate the general concept of
  | conversations from the details of particular protocols, so that each
  | type of conversation would supply its own matching code.

That sounds better. That could replace the existing special
cases for PT_UDP and AT_FC too.

Attachment: pgpbdQBDEjtXx.pgp
Description: PGP signature