2. Introduction
• pcap-map is a web application that visualizes a
network traffic trace on a map.
• You may use pcap-map to:
• see where are the websites you have visited, using a
trace from a laptop;
• see where are the clients of your website, using a trace
from a server.
3. How to Use
1. collect network traffic trace with tcpdump or
Wireshark
• save as libpcap 2.4 format (.pcap, not .pcapng)
2. load the trace into pcap-map web application
3. select the type of visualization you want to see
4. Available Visualizations
• Host plot: where are the hosts
• TCP: HTTP servers, HTTPS servers, other TCP
• UDP: DNS servers, other UDP
• Heat map: how many packets came from a region
• TCP and UDP
5. Technical Overview
• The trace is parsed entirely in browser.
• HTML5 Web Workers, FileReaderSync
• hand-written parsers for pcap, Ethernet header, IPv4
header, TCP header, UDP header
• IP addresses found in the trace are sent to the
server to lookup geoip database.
• MaxMind GeoLite2 database
• Geographical locations of IP addresses are plotted
on a world map.
• Google Maps API
• Google Maps visualization library