46 lines
1.5 KiB
Markdown
46 lines
1.5 KiB
Markdown
# Wireshark VRU Awareness Service (VAM) Dissector Extension
|
|||
|
|
|
||
|
|
## Purpose
|
||
|
|
Wireshark natively dissects IEEE 1609.2 / ETSI TS 103 097 secured packets, but stops dissecting at `Ieee1609Dot2Data.unsecuredData` unless the ITS Application ID (PSID) is registered in Wireshark's internal `ieee1609dot2.psid` dissector table.
|
||
|
|
|
||
|
|
- Standard PSIDs like CAM (`36`) and DENM (`37`) are registered by default in Wireshark 4.x.
|
||
|
|
- **PSID 638** (VRU Awareness Service, ETSI TS 102 965) is not registered in Wireshark 4.x.
|
||
|
|
|
||
|
|
This Lua plugin registers **PSID 638** to point to the GeoNetworking common header (`gnw.comm`), allowing Wireshark to continue dissecting the entire stack:
|
||
|
|
```
|
||
|
|
IEEE 802.11 (5.9 GHz ITS-G5) -> LLC/SNAP 0x8947 -> GeoNetworking -> BTP-B (port 2018) -> VAM (TS 103 300-3)
|
||
|
|
```
|
||
|
|
|
||
|
|
## Installation
|
||
|
|
|
||
|
|
### Windows
|
||
|
|
Copy `psid-vru.lua` into your personal Wireshark plugins directory:
|
||
|
|
```powershell
|
||
|
|
Copy-Item tools/wireshark/psid-vru.lua "$env:APPDATA\Wireshark\plugins\"
|
||
|
|
```
|
||
|
|
|
||
|
|
### Linux
|
||
|
|
Copy `psid-vru.lua` into:
|
||
|
|
```bash
|
||
|
|
mkdir -p ~/.local/lib/wireshark/plugins
|
||
|
|
cp tools/wireshark/psid-vru.lua ~/.local/lib/wireshark/plugins/
|
||
|
|
```
|
||
|
|
|
||
|
|
### macOS
|
||
|
|
Copy `psid-vru.lua` into:
|
||
|
|
```bash
|
||
|
|
mkdir -p ~/.config/wireshark/plugins
|
||
|
|
cp tools/wireshark/psid-vru.lua ~/.config/wireshark/plugins/
|
||
|
|
```
|
||
|
|
|
||
|
|
## Verification
|
||
|
|
1. Open Wireshark.
|
||
|
|
2. Navigate to **Help -> About Wireshark -> Plugins**.
|
||
|
|
3. Verify that `psid-vru.lua` is listed as active.
|
||
|
|
|
||
|
|
## Command-Line Usage (tshark)
|
||
|
|
You can directly pass the Lua script to `tshark` without installing:
|
||
|
|
```bash
|
||
|
|
tshark -X lua_script:tools/wireshark/psid-vru.lua -r capture.pcap
|
||
|
|
```
|