当前位置:网站首页>Wireshark introduction and packet capturing principle and process
Wireshark introduction and packet capturing principle and process
2022-07-25 00:45:00 【Pheebs Mustang】
WireShark Introduction to the principle and process of packet capture

- WireShark brief introduction
Wireshark Is a network packet analysis software , You can capture and analyze packets , It can run on the current mainstream operating system :Windows,Linux,macOS. The function of network packet analysis software is to extract network packets , And show the most For detailed network packet information .Wireshark Use WinPCAP As an interface , Data message exchange with network card directly . For safety reasons ,wireshark Only packets can be viewed , You cannot modify the data in the packet , Can't send packets .
- WireShark Application
Used by network administrators Wireshark To detect network problems , Network security engineers use Wireshark To check information security related problem , Developers use Wireshark To debug the new communication protocol , Ordinary users use Wireshark To learn about network protocols Relevant knowledge . Of course , Some people will “ Harbour evil intent designs ” Use it to find some sensitive information .
- WireShark Quick packet analysis techniques
(1) determine Wireshark The physical location of . If you don't have a correct position , start-up Wireshark It will take a long time Capture some data irrelevant to yourself .
(2) Select capture interface . Generally, you choose to connect to Internet Network interface , Only in this way can we capture network related data . otherwise , The other data captured will not help you .
(3) Use capture filters . By setting the capture filter , It can avoid generating too large capture data . So users are analyzing data when , It will not be disturbed by other data . and , It can also save users a lot of time .
(4) Use display filters . Capture filters are usually used to filter the data , It's often complicated . In order to filter packets More detailed , Use the display filter to filter .
(5) Use shading rules . The data filtered by the display filter is usually used , Are useful packets . If you want to be more prominent Show a session , You can highlight using shading rules .
(6) Building charts . If users want to see more clearly the changes of data in a network , Using chart form can be very square Easily show the data distribution .
(7) Reorganizing data . When transferring large pictures or files , The information needs to be distributed in multiple packets . You need to use Reorganize the data to capture the complete data .Wireshark Recombination function of , You can reorganize the information of different packets in a session , or It is to reorganize a complete picture or file .
边栏推荐
- Kusionstack open source | exploration and practice of kusion model library and tool chain
- The use of where condition in MySQL is not equal to! = The problem that null values are filtered out occurs when in, etc
- Promtool Check
- Why does [mindspore ascend] [custom operator] repeatedly assign values to one tensor affect another tensor?
- Unity+photon self made multiplayer TPS game
- Kubernetes application design guide
- Heap and stack in embedded development
- Unity image control and rawimage
- Which automation tools can double the operation efficiency of e-commerce?
- NXP i.mx6q development board software and hardware are all open source, and the schematic diagram of the core board is provided
猜你喜欢

Financial RPA robot enables enterprises to open a new era of intelligence

Automated test series selenium three kinds of waiting for detailed explanation
![Why does [mindspore ascend] [custom operator] repeatedly assign values to one tensor affect another tensor?](/img/e3/135ac1e6eade70082c205d16ab8e34.jpg)
Why does [mindspore ascend] [custom operator] repeatedly assign values to one tensor affect another tensor?

What are the functions of rank function
![[hero planet July training leetcode problem solving daily] 24th line segment tree](/img/ae/1f3288a99cb07fcbb1836357e0229a.png)
[hero planet July training leetcode problem solving daily] 24th line segment tree

UART
![[Bert] transformer/bert/attention interview questions and answers](/img/32/5d29ce8056df16211630c3384adcf4.png)
[Bert] transformer/bert/attention interview questions and answers

Tencent low code platform is officially open source! You can drag and drop and generate mobile phone projects and PC projects! Get private benefits

Internal network mapping port to external network
![[mindspore ascend] [running error] graph_ In mode, run the network to report an error](/img/81/9e96182be149aef221bccb63e1ce96.jpg)
[mindspore ascend] [running error] graph_ In mode, run the network to report an error
随机推荐
Nodejs package
Install and configure php5-7 version under centos7.4
What is the function of transdata operator and whether it can optimize performance
Redis 事务学习有感
If real-time intersection with line segments in online CAD drawings is realized
数组中只出现一次的两个数字
Notes on topic brushing (XXII) -- Dynamic Planning: basic ideas and topics
Big talk · book sharing | Haas Internet of things device cloud integrated development framework
第三章 内核开发
Detailed usage of iperf
[acwing weekly rematch] 61st weekly 20220723
[leetcode weekly replay] game 83 biweekly 20220723
阿里 Seata 新版本终于解决了 TCC 模式的幂等、悬挂和空回滚问题
Redis管道技术/分区
UXDB在不知道明文密码的情况下重置密码
EF core :自引用的组织结构树
Research and Multisim Simulation of linear circuit characteristics (engineering documents attached)
Method properties of ASP adodb.stream object
Advanced multithreading (Part 2)
Quartus:17.1版本的Quartus安装Cyclone 10 LP器件库