accessing TCP socket hash tables from user space or kernel module

From: Kah Hwee Chua (
Date: Thu Feb 06 2003 - 13:22:40 EST


I am trying to come up with a network monitor (both as kernel module or as a
user program) that is able to recognize TCP packets streaming into a
particular socket.

I would thereupon want to obtain the PID of the process listening to the
particular socket so that I can set higher scheduling priority for it.

Currently, I've setup my network monitoring from the network device driver
to tap the destination address of the incoming packet but I've yet to be
able to access or read the TCP socket hash table.

Any advice on how to carry this out?

Thanks and best regards,
KahHwee, Chua

