A passive network fingerprinting tool developed for our Cybersecurity class. It analyzes local traffic (ARP, DHCP, mDNS, SSDP) to detect devices and guess the environment type (Home vs. Corporate) based on vendor hardware.
There are two implementations included here, showcasing the evolution from a passive sniffer to an intelligent analysis engine.
My individual contribution focused on the core sniffing architecture and protocol parsing.
network.cpp(Core): Acts as a lightweight daemon. It uses PcapPlusPlus to capture packets, parses headers (ARP, DHCP, mDNS), and serializes the raw data intonetwork_capture.json. It does not perform any analysis; it strictly collects data.fronthand.py: (name is a joke :D) The "brain" of this version. It reads the JSON logs in real-time and performs the heuristic analysis (calculating Home vs. Work scores) externally.
We significantly upgraded the backend, moving the analysis logic directly into the C++ layer for performance and added a graphical interface.
network.cpp(Extended Analysis): The backend was transformed from a passive collector into an active decision engine.- Internal Scoring System: We implemented the scoring logic directly in C++ using an in-memory
unordered_mapto track vendors and scores in real-time, removing the dependency on Python for calculation. - SSDP Keyword Classification: Added logic to parse SSDP "Notification Types" and service headers to detect specific devices (e.g., Xbox, Sonos, Printer) and adjust scores dynamically.
- Traffic Deduplication: Implemented a hash set (
scoredMacs) to prevent chatty devices from inflating scores by spamming packets. - Probability Math: The C++ code now calculates the final "Confidence Score" and probability percentages (Home% vs Corporate%) internally before sending the final report to the GUI.
- Internal Scoring System: We implemented the scoring logic directly in C++ using an in-memory
frontend.py: A Tkinter application that visualizes the data stream and manages the C++ subprocess.
- Passive Only: No active scanning or flooding.
- Fingerprinting: Uses DHCP (Option 55/60), mDNS, and SSDP to identify OS types and services.
- OUI Lookup: Identifies manufacturers via MAC headers.
- Scoring Logic: Assigns points based on vendors (e.g., Nintendo = Home, Cisco = Office).
- G++ / Make / libpcap-dev
- PcapPlusPlus
- Python 3.x (with
tkinter)
To respect copyright and licensing terms, the vendor database files (ieee-oui.txt and oui_scored.txt) are not included in this repository. You must generate them yourself.
- Download the OUI Standard: Get the official list from the IEEE website: https://standards-oui.ieee.org/
- Format the Database: The C++ parser expects a text file named
ieee-oui.txtwhere lines are formatted roughly as:AA-BB-CC (hex) VENDOR_NAME - Scoring File (
oui_scored.txt): For the scoring logic to work, create a pipe-delimited text file mapping MAC prefixes to scores:AABBCC|VendorName|HomeScore|WorkScore