Network Mode - Live Packet Capture
Network Mode - Live Packet Capture
Live capture from a network interface for quantum-vulnerable TLS and SSH cryptographic handshakes
The network command performs live capture from a network interface and requires the scanner to be built with the pcap-live feature (plus the system capture library — libpcap/Npcap). It is a different command from Packet Capture, which analyzes an already-captured .pcap/.pcapng file offline and only requires the pcap feature.
Overview
Network mode captures traffic live from a network interface, reconstructs network flows, and parses cryptographic handshakes to assess PQC readiness. Unlike domain mode (which actively connects to a specific endpoint), network mode passively observes whatever TLS/SSH traffic crosses the interface.
Capabilities
Live Interface Capture
Captures directly from a network interface (libpcap/Npcap) — no capture file needed
TLS 1.2/1.3 Parsing
Extracts ClientHello, ServerHello, supported groups, key shares, and SNI
SSH 2.0 Parsing
Parses KEXINIT messages for key exchange algorithm negotiation
PQC Detection
Identifies post-quantum and hybrid key exchanges (ML-KEM, Kyber, SNTRUP)
How It Works
Open the Interface
The scanner opens the specified network interface (requires elevated privileges).
Capture and Track Flows
It reconstructs bidirectional network flows using 5-tuple keys (src IP, src port, dst IP, dst port, protocol), for up to the configured capture duration or flow limit.
Parse Handshakes
The scanner extracts and parses TLS ClientHello/ServerHello and SSH KEXINIT messages from the reconstructed flows.
Classify Findings
Each connection is classified as PQC-ready (safe) or classical-only (quantum-vulnerable), with risk scores and severity levels.
Usage
# Live-capture on eth0
sudo dke-scanner-agent network --interface eth0
# Bound the capture duration (seconds) and save results
sudo dke-scanner-agent network --interface eth0 --capture-duration-secs 300 --output results.json
# Filter to TLS traffic only
sudo dke-scanner-agent network --interface eth0 --bpf-filter "tcp port 443"
# Keep only PQC-relevant findings
sudo dke-scanner-agent network --interface eth0 --pqc-only
CLI Options
| Option | Description | Default |
|---|---|---|
| -i, --interface <IF> | (Required) Interface to capture from (e.g. eth0) | - |
| --capture-duration-secs <SECS> | Capture duration in seconds | Unbounded |
| --max-flows <N> | Maximum number of flows to track | Unbounded |
| --bpf-filter <FILTER> | Optional BPF filter (e.g. "tcp port 443") | - |
| --pqc-only | Keep only PQC-relevant findings | false |
| -o, --output <FILE> | Output file path (stdout if not specified) | - |
| --format <FMT> | Output format: json, summary | json |
Live capture typically requires elevated privileges (root / Administrator) to open the network interface. For analyzing traffic already captured to a file with a tool like tcpdump or Wireshark, use Packet Capture instead.
PQC Detection
The scanner detects post-quantum key exchange algorithms in both TLS and SSH handshakes:
TLS Named Groups
| Category | Algorithms | Status |
|---|---|---|
| Hybrid PQC (IANA registered) | X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024 | PQ-Safe |
| Pure ML-KEM (FIPS 203) | MLKEM512, MLKEM768, MLKEM1024 | PQ-Safe |
| Pre-standard Kyber | Kyber768_draft, Kyber1024_draft | PQ-Safe (draft) |
| OQS Test IDs | OQS_Kyber512, OQS_Kyber768, OQS_Kyber1024 | PQ-Safe (experimental) |
| OQS Hybrid | X25519_Kyber768, SecP256r1_Kyber768 | PQ-Safe (experimental) |
| Classical only | X25519, P-256, P-384, FFDHE, etc. | Quantum-Vulnerable |
SSH KEX Algorithms
| Algorithm | Type | Status |
|---|---|---|
| [email protected] | Hybrid (SNTRUP + X25519) | PQ-Safe |
| mlkem768x25519-sha256 | Hybrid (ML-KEM + X25519) | PQ-Safe |
| mlkem1024x448-sha512 | Hybrid (ML-KEM + X448) | PQ-Safe |
| kyber-512-sha256 | Pure Kyber | PQ-Safe |
| kyber-768-sha384 | Pure Kyber | PQ-Safe |
| kyber-1024-sha512 | Pure Kyber | PQ-Safe |
| curve25519-sha256, ecdh-sha2-nistp256, etc. | Classical | Quantum-Vulnerable |
Risk Classification
| Finding | Severity | Priority | Description |
|---|---|---|---|
| PQ key exchange detected | Info | P4 | Connection uses post-quantum or hybrid key exchange - safe against quantum attacks |
| Classical-only key exchange | High | P1 | Connection uses only classical algorithms - vulnerable to harvest-now-decrypt-later attacks |
Flow Tracking
The scanner reconstructs bidirectional network flows using canonical 5-tuple keys:
- Source IP and Destination IP
- Source Port and Destination Port
- Protocol (TCP)
Packets in both directions are matched to the same flow. Each flow tracks first_seen, last_seen, and packet_count timestamps. Flow tracking is unbounded by default; pass --max-flows to cap memory usage on a long-running capture.
For a very long capture, use --max-flows to control memory usage. Flows beyond the limit are silently dropped.
Use Cases
Production Traffic Audit
Capture live production traffic to discover all TLS endpoints and their cryptographic parameters
PQ Migration Verification
After deploying PQ-capable TLS configurations, capture traffic and verify that clients are negotiating PQ key exchanges
Cipher Suite Compliance
Analyze captured traffic to verify all TLS connections use approved cipher suites and algorithms
SSH Security Assessment
Analyze SSH traffic to verify key exchange algorithms are PQ-ready across your infrastructure
Complementary Modes
Network mode works best in combination with other scanning modes:
- Domain mode with
--pqc: Active PQ key exchange detection for specific targets - Packet Capture: Offline analysis of an already-captured
.pcap/.pcapngfile - Inventory mode: System-level certificate and keystore discovery
- Filesystem mode: Certificate file analysis on disk
For a complete cryptographic posture assessment, combine network analysis (what's negotiated on the wire) with filesystem/inventory scanning (what's deployed on disk).