Ask Your Question
0

Why is this Canon BJNP protocol in the Protocol Hierarchy Statistics?

asked 2023-05-08 02:02:41 +0000

0internetuser1 gravatar image

Here are 2 screenshots https://imgur.com/a/8gua4uu

I don't have any Canon devices. Does Wireshark misidentify things to this extent? I'm using Brave browser, and occasionally playing a few games from legal sources.

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted
0

answered 2023-05-08 05:35:18 +0000

Jaap gravatar image

When looking at the dissector, any UDP packet on port 8611-8614 which has a printable character at the start is considered a Canon BJNP packet. Also the services file identifies these ports as used for Canon BJNP. However, these are not reserved ports, so it's not inconceivable that another use is made of these ports, with another protocol. That is what seems to be the case here.

edit flag offensive delete link more

Comments

And, other than the port range check, that's a fairly weak heuristic, so, yes, Wireshark does misidentify things to this extent. If more tests could be added to the Canon BJNP dissector so that it misidentifies fewer packets, that should be done.

Guy Harris gravatar imageGuy Harris ( 2023-05-08 20:00:29 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: 2023-05-08 02:02:41 +0000

Seen: 438 times

Last updated: May 08 '23