According to the ebook, pg 245(reader)/pg 222(book), the paragraph right above "Writing Capture Filters", the author states that the PCAP library aka Capture Filter may not be as powerful as the Display Filter of Wireshark, resulting in the latter requires more execution time.
My question: is Capture Filter (libpcap / Winpcap) capable of filtering data as deep as the SS7 application layer..
Correct: libpcap does not currently have (capture) filters for SS7. It's not that it could not, but no one has implemented it.
answered 26 Jul '11, 07:05
Depending on your requirements you could work around those limitations.
1) You could extend the wireshark/tshark with lua and packet tap which would save packets that match certain filters into separate files
2) You could capture files with tcpdump/dumpcap pipe them them to tshark which can then apply -R "display_filter" option
answered 26 Jul '11, 07:29