7. pcapngの現状
ツールの対応状況が追いついていない
Wiresharkの現状
https://wiki.wireshark.org/Development/PcapNg
The current limitations for pcapng format are:
Only a single section
Only blocks SHB, IDB, PB, EPB, SPB (others will be ignored)
Lots of Options not implemented
Writing ?les is mostly untested
When merging ?les, mergecap doesn't retain each IDB's snaplen
mergecap won't merge pcapng ?les with different encapsulations and
intermixed timestamps
というか放置状態????
defaultになったのは2012年
あまりアップデートはない