¼ÆËã»úÍøÂçʵÑé - ͼÎÄ ÏÂÔØ±¾ÎÄ

Îå¡¢²Ù×÷·½·¨ÓëʵÑé²½Öè

1¡¢·ý»ñ±¾»úÓëÔ¶³Ì·þÎñÆ÷µÄTCP ×Ù¼£Îļþ

ÔÚ¿ªÊ¼Ñо¿ TCP ¹¤×÷»úÖÆÖ®Ç°£¬ÐèҪʹÓÃWireshark À´·ý»ñ´Ó±¾»úµ½Ô¶³Ì·þÎñÆ÷Ö®¼äµÄTCP ×Ù¼£Îļþ¡£Îª´Ë£¬¿ÉÒÔ´Ó±¾»úä¯ÀÀÆ÷´ò¿ªÄ³Web ÍøÕ¾ÉϵÄÍøÒ³£¬ÓÃHTTP ЭÒéÏÂÔØ°üÀ¨Îı¾ÎļþÔÚÄڵĶÔÏó¡£Óë´Ëͬʱ£¬ÔÚ±¾»úÉÏÔËÐÐWireshark ·ý»ñ±¾»úÊÕ·¢µÄTCP ±¨ÎĶβ¢´æÈë×Ù¼£Îļþtcp.cap ÖС£ÎªÁ˱ãÓڱȽϣ¬¿ÉÒÔ´ÓÒòÌØÍøÉÏÏÂÔØÏֳɵÄ×Ù¼£Îļþ½øÐзÖÎö£¬Ïà¹Øhttp://gaia.cs.umass.edu/wireshark-labs/wireshark-traces.zip¡£

URL ÊÇ

2¡¢ÊìϤTCP ×Ù¼£Îļþ

´ò¿ª tcp-ethereal-trace-1.pcap Îļþ£¬¿ÉÒÔ¿´µ½·ý»ñ»úÆ÷Óëgaia.cs.umass.edu µÄWeb ·þÎñÆ÷Ö®¼ä½»»¥µÄTCP ºÍHTPP ±¨ÎÄÐòÁÐ(²Î¼ûͼ1)¡£Ñ¡ÔñÒ»¸ö±¨ÎÄ£¬¹Û²ìÆä¸÷²ã´ÎЭÒé¼äµÄ°üº¬¹ØÏµ¡£¹Û²ì HTTP ÓëTCP Ö®¼ä¹ØÏµÊÇÈçºÎÌåÏֵ쬴ӷý»ñ±¨ÎÄÁÐ±í´°¿ÚÓҲ࣬¿ÉÒÔ·¢ÏÖ·¢ÆðÈý´ÎÎÕÊÖµÄSYN ±¨ÎÄ£¬Ò²¿ÉÒÔ·¢ÏÖһϵÁн»»¥µÄHTTP ±¨ÎÄ¡£

3¡¢·ÖÎöTCP ÐòÁÐ/Ó¦´ð±àºÅºÍÁ÷Á¿¿ØÖÆ

Ϊ·ÖÎö TCP ÐòºÅºÍÈ·ÈϺţ¬¿ÉÒÔ´Ó·Ö×éÁбíÖй۲죬Ҳ¿ÉÒÔµã»÷¡°Statitics/Flow Graph¡±£¬³öÏÖÈçͼ2 ËùʾµÄ±¾»úÓë·þÎñÆ÷Ö®¼äµÄͼ·ÖÎö½á¹û¡£

4¡¢·ÖÎöÓ¦ÓòãÄÚÈÝ

±¾ÊµÑéÖеÄÓ¦ÓòãÊÇ HTTP£¬¸ÃЭÒéµÄ¿É¿¿´«Êä»ùÓÚTCP µÃµ½µÄ¡£Í¨¹ý·ÖÎöTCP ±¨ÎÄÐòÁпÉÒԵõ½HTTP ´«ÊäµÄÄÚÈÝ¡£Îª´Ë£¬µã»÷TCP Èý´ÎÎÕÊÖÖ®¼äµÄµÚ4 ºÅ±¨ÎÄ£¬·¢ÏÖËüÊÇÒ»Ìõ´Ó±¾»úÏò·þÎñÆ÷·¢ËÍHTTP POST ÃüÁîµÄ±¨ÎÄ£¬ÇëÇóWeb ·þÎñÆ÷·¢ËÍÌØ¶¨µÄÒ³Ãæ¶ÔÏó¡£¶ÔÓÚºó¼Ì±¨ÎÄ£¬Ò²¿ÉÒÔ·¢ÏÖÒÔASCII Ã÷ÎÄ·¢Ë͵ÄÓ¦ÓòãÄÚÈÝ¡£

¶ÔÓÚ·ÖÎöÓ¦ÓòãÄÚÈÝ£¬Wireshark ÌṩÁËÒ»¸öºÜºÃµÄ¹¤¾ß¡£µã»÷¡°Analyze/Follow TCP Stream¡±£¬¿É´ò¿ªÈçͼ3 Ëùʾ½çÃæ£¬ÏÔʾÁ˸ÃTCP Á÷µÄÓ¦ÓòãÏà¹ØÐÅÏ¢¡£

24

5¡¢·ÖÎöTCP ÓµÈû¿ØÖÆ

µã»÷¡°Statistics/TCP Stream Graph/Throughput Gragh¡±£¬µÃµ½Èçͼ4 ËùʾµÄ½çÃæ¡£Í¼ÖеÄÿ¸öµã±íʾÔÚijʱ¿Ì¸ÃTCP Á¬½ÓµÄÍÌÍÂÁ¿¡£

Áù¡¢ÊµÑéÊý¾Ý¼Ç¼ºÍ½á¹û·ÖÎö

ͼ1 ÊìϤTCP ×Ù¼£Îļþ

ͼ2 ·ÖÎöTCP ÐòÁÐ/Ó¦´ð±àºÅºÍÁ÷Á¿¿ØÖÆ

25

ͼ3 ·ÖÎöÓ¦ÓòãÄÚÈÝ

ͼ4 ·ÖÎöTCP ÓµÈû¿ØÖÆ

26

Æß¡¢ÊµÑéÌå»á¡¢ÖÊÒɺͽ¨Òé

ËäÈ»WireSharkΪÎÒÃÇ·ÖÎöTCPЭÒé°üÌṩÁËÒ»¸öºÜºÃµÄ¿ÉÊÓ»¯»·¾³£¬µ«ÎÒÃÇѧϰTCPЭÒé²»ÄÜֻͣÁôÔÚËüÏÔʾµÄͳ¼ÆÊý¾ÝºÍ·ÖÎö½á¹ûÉÏÃæ£¬»¹ÒªÖªµÀËüΪʲôµÃ³öÕâÑùµÄ·ÖÎö½á¹û£¬´Ó¶øÉî¿ÌÀí½âTCPЭÒéʵÏÖ¿É¿¿Á¬½ÓºÍÓµÈû¿ØÖƵŤ×÷Ô­Àí£¬½«ÀíÂÛºÍʵ¼ù½áºÏ£¬ÉѧϰЧ¹û¡£

27