Anewertoolcalled tcpflow complements tcpdump and provides a way to do protocolflowanalysisand to properlyreconstructdatastreams, regardlessofpacketorderorretransmissions.
Born as an IPS solution NetASQ rapidly leveraged their ability to do deep packet inspection, (or, as IDC terms it, complete content inspection) to apply policies based not just on source-destination-port, but on content of assembled packetstreams.