Process ID

Home Forums Discussions Support Portal Process ID

This topic contains 1 reply, has 2 voices, and was last updated by  Vadim Smirnov 13 years ago.

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
  • #5006


    Is it possible to determine the process ID for a packet read using WinpkFilter (might be useful for implementing a firewall for example)?


    Vadim Smirnov

    Process context is not available at the NDIS level where WinpkFilter works. In order to determine the packet associated process you should obtain the current connections table on some way (TDI filter, LSP and some other less popular ways) and match packet to the process using address/port information.

    Usually, firewall is a combination of NDIS level filter (packet firewall) and application level filter (application/desktop firewall).

    Hope it helps

Viewing 2 posts - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.