Flow direction

Huy N. Hang hangh at cs.ucr.edu
Sat May 21 20:40:05 EDT 2011


Hi everyone,

I'm starting to wonder about the dir field produced by ra.

Since it actually shows the direction of the flow in the case of TCP, and
it can even be "<-", do the field names "SrcAddr" and "DstAddr" remain
significant in that case?

I mean, if SrcAddr is where the flow originates, does the dir field "<-"
not contradict that?

Thanks!




More information about the argus mailing list