TCP Tracepoints have arrived in Linux
brendangregg.com
brendangregg.com
I'm particularly excited about the retransmit tracepoints, as troubleshooting some of these issues on systems that can't afford the tcpdump overhead has caused me significant headache in the past.
For older kernels, there is a ftrace way for tracing retransmits: http://www.brendangregg.com/blog/2014-09-06/linux-ftrace-tcp...
The oldest are SNMP style counters used by "netstat -s" / "sar -n ETCP" for all retransmits on the system, if you don't need per flow stats.
Ten there's an application level getsockopt TCP_INFO, detailed at: https://linuxgazette.net/136/pfeiffer.html
I did once (over 10 years ago now) develop a tool that would, upon receiving a packet from a new source, perform an OS fingerprint on it and if it turned out to be Microsoft Windows, block it once the fingerprinting process returned... :-) This tool actually just fired off a script (JIT compiled) for every packet that matched pre-defined criteria and that script could return a verdict on what to do with that packet, which could involve inspecting userspace connections trivially
Haven't used it though.
Do you (or anyone else here) know if something like this exists already, or is in the pipeline, for raw sockets in Linux?