NetFilter SDK WFP driver

NetFilter SDK is a framework for transparent filtering of the data packets transmitted via network. This is a high-performance proxy-less solution, compatible with antiviruses/firewalls/other network filters. It is suitable for developing content filters, basic application level firewalls, traffic analyzers/shapers, and other software that requires viewing and modifying TCP/UDP traffic on Windows.

The SDK consists of kernel-mode and user-mode parts. The WFP kernel driver works on top of the TCP/IP stack and filters TCP/UDP protocols. Additionally, it is possible to filter any IP-based protocols on packet layers. It has a simple user-mode API, which can be used from C/C++/.NET/Delphi code.

Key features

  • The solution allows filtering incoming/outgoing TCP connections and UDP datagrams in user mode application. It is possible to filter the specified subset of connections/datagrams, restricted by filtering rules. The outgoing TCP connections can be redirected to a different address.

  • By default, the filtering is transparent to other filters, because the driver allows viewing and changing TCP/UDP data without redirecting the traffic to proxy and modifying the addresses. It minimizes the probability of conflicts with antiviruses, firewalls and other filters.

  • The filtering driver operates at the transport level, on top of the TCP/IP stack. As a result, it automatically supports all kinds of TCP/IP capable network adapters: Ethernet, Dial-up/DSL/Cable modems, wireless adapters including Wi-Fi and Bluetooth, virtual adapters like loopback or VPN.

  • Both IPv6 and IPv4 are supported.

  • The process context (such as the process identifier) is available for all network activity.

  • The driver user-level interface (API) is easy to use, but powerful.

  • It is possible to control the speed of data transmission and count the traffic.

  • The driver works in the same way on 32-bit and 64-bit Windows operating systems. It is possible to use 32-bit API for working with 64-bit driver.