Files
MicrOBU/microbu-esp32c5/tools/wireshark/README.md
T

46 lines
1.5 KiB
Markdown
Raw Normal View History

# Wireshark VRU Awareness Service (VAM) Dissector Extension
## Purpose
Wireshark natively dissects IEEE 1609.2 / ETSI TS 103 097 secured packets, but stops dissecting at `Ieee1609Dot2Data.unsecuredData` unless the ITS Application ID (PSID) is registered in Wireshark's internal `ieee1609dot2.psid` dissector table.
- Standard PSIDs like CAM (`36`) and DENM (`37`) are registered by default in Wireshark 4.x.
- **PSID 638** (VRU Awareness Service, ETSI TS 102 965) is not registered in Wireshark 4.x.
This Lua plugin registers **PSID 638** to point to the GeoNetworking common header (`gnw.comm`), allowing Wireshark to continue dissecting the entire stack:
```
IEEE 802.11 (5.9 GHz ITS-G5) -> LLC/SNAP 0x8947 -> GeoNetworking -> BTP-B (port 2018) -> VAM (TS 103 300-3)
```
## Installation
### Windows
Copy `psid-vru.lua` into your personal Wireshark plugins directory:
```powershell
Copy-Item tools/wireshark/psid-vru.lua "$env:APPDATA\Wireshark\plugins\"
```
### Linux
Copy `psid-vru.lua` into:
```bash
mkdir -p ~/.local/lib/wireshark/plugins
cp tools/wireshark/psid-vru.lua ~/.local/lib/wireshark/plugins/
```
### macOS
Copy `psid-vru.lua` into:
```bash
mkdir -p ~/.config/wireshark/plugins
cp tools/wireshark/psid-vru.lua ~/.config/wireshark/plugins/
```
## Verification
1. Open Wireshark.
2. Navigate to **Help -> About Wireshark -> Plugins**.
3. Verify that `psid-vru.lua` is listed as active.
## Command-Line Usage (tshark)
You can directly pass the Lua script to `tshark` without installing:
```bash
tshark -X lua_script:tools/wireshark/psid-vru.lua -r capture.pcap
```