import struct, sys, time, collections
f=sys.argv[1]; mins=float(sys.argv[2]) if len(sys.argv)>2 else 15
now=time.time(); cut=now-mins*60
C='62.33.118.242'; S='91.233.121.88'
d=open(f,'rb').read()
end='<' if d[:4] in (b'\xd4\xc3\xb2\xa1', b'\x4d\x3c\xb2\xa1') else '>'
off=24; first=None; lastf=None
stats=collections.defaultdict(lambda:[0,0]); hists=collections.defaultdict(collections.Counter)
while off+16<=len(d):
    ts,us,inc,orig=struct.unpack(end+'IIII', d[off:off+16]); off+=16
    pkt=d[off:off+inc]; off+=inc
    if first is None: first=ts
    lastf=ts
    if ts<cut or len(pkt)<34 or pkt[12:14]!=b'\x08\x00': continue
    if pkt[23]!=17: continue
    src='.'.join(str(x) for x in pkt[26:30]); dst='.'.join(str(x) for x in pkt[30:34])
    if src==C and dst==S: k='C->S'
    elif src==S and dst==C: k='S->C'
    else: continue
    ulen=struct.unpack('>H',pkt[16:18])[0]
    stats[k][0]+=1; stats[k][1]+=ulen; hists[k][ulen]+=1
fmt=lambda t: time.strftime('%H:%M:%S',time.gmtime(t)) if t else '-'
print('file span: %s .. %s UTC' % (fmt(first), fmt(lastf)))
print('window: last %.0f min (now %s UTC)' % (mins, fmt(now)))
for k in ('C->S','S->C'):
    c,b=stats[k]
    print('%s pkts=%d bytes=%d' % (k,c,b))
    print('   sizes:', ', '.join('%d:%d'%(s,n) for s,n in sorted(hists[k].items())[:25]))
