SKIP TO CONTENT
← ALL OPENINGSNF3 · THE RUY LOPEZ
PROJECT 02

Network Packet Analyzer

Real-time Capture & Security Assessment Tool

8,200
packets/second — 7.4× over the baseline
PythonScapyTkinterThreading
FIG. NETWORK PACKET ANALYZERLIVE TRACE
01

THE PROBLEM

A packet analyzer that freezes under peak load is worse than no analyzer: the GUI stops telling the truth exactly when traffic gets interesting.

02

THE APPROACH

Decouple the sniffer from the interface with a bounded queue, remove redundant serialization, and measure p99 latency instead of averages.

03

THE ARCHITECTURE

  1. 01
    NIC capture (Scapy)
    ↓
  2. 02
    Bounded queue
    ↓
  3. 03
    Worker threads
    ↓
  4. 04
    Alert rules
    ↓
  5. 05
    Tkinter GUI + session export
04

THE IMPLEMENTATION

  1. 01Built a multithreaded capture pipeline that decouples the Scapy sniffer from the Tkinter GUI through a bounded queue.
  2. 02Engineered four real-time alert rules — SYN flood, port scan, credential leak, oversized flow.
  3. 03Added session export to PCAP, CSV and JSON with a lightweight memory footprint.
05

THE RESULTS

  • Throughput lifted 7.4× — 1,107 → 8,200 PPS.
  • p99 latency cut to 442 μs; a 0.500 precision regression on the alert rules was found and fixed.
06

WHAT I LEARNED

“Sometimes the fastest code is the code you delete — remove the serialization, keep the truth.”

07

TECH STACK

Python
Scapy
Tkinter
Threading
Networking