Îå¡¢²Ù×÷·½·¨ÓëʵÑé²½Öè
1¡¢·ý»ñ±¾»úÓëÔ¶³Ì·þÎñÆ÷µÄTCP ×Ù¼£Îļþ
ÔÚ¿ªÊ¼Ñо¿ TCP ¹¤×÷»úÖÆÖ®Ç°£¬ÐèҪʹÓÃWireshark À´·ý»ñ´Ó±¾»úµ½Ô¶³Ì·þÎñÆ÷Ö®¼äµÄTCP ×Ù¼£Îļþ¡£Îª´Ë£¬¿ÉÒÔ´Ó±¾»úä¯ÀÀÆ÷´ò¿ªÄ³Web ÍøÕ¾ÉϵÄÍøÒ³£¬ÓÃHTTP ÐÒéÏÂÔØ°üÀ¨Îı¾ÎļþÔÚÄڵĶÔÏó¡£Óë´Ëͬʱ£¬ÔÚ±¾»úÉÏÔËÐÐWireshark ·ý»ñ±¾»úÊÕ·¢µÄTCP ±¨ÎĶβ¢´æÈë×Ù¼£Îļþtcp.cap ÖС£ÎªÁ˱ãÓڱȽϣ¬¿ÉÒÔ´ÓÒòÌØÍøÉÏÏÂÔØÏֳɵÄ×Ù¼£Îļþ½øÐзÖÎö£¬Ïà¹Øhttp://gaia.cs.umass.edu/wireshark-labs/wireshark-traces.zip¡£
URL ÊÇ
2¡¢ÊìϤTCP ×Ù¼£Îļþ
´ò¿ª tcp-ethereal-trace-1.pcap Îļþ£¬¿ÉÒÔ¿´µ½·ý»ñ»úÆ÷Óëgaia.cs.umass.edu µÄWeb ·þÎñÆ÷Ö®¼ä½»»¥µÄTCP ºÍHTPP ±¨ÎÄÐòÁÐ(²Î¼ûͼ1)¡£Ñ¡ÔñÒ»¸ö±¨ÎÄ£¬¹Û²ìÆä¸÷²ã´ÎÐÒé¼äµÄ°üº¬¹ØÏµ¡£¹Û²ì HTTP ÓëTCP Ö®¼ä¹ØÏµÊÇÈçºÎÌåÏֵ쬴ӷý»ñ±¨ÎÄÁÐ±í´°¿ÚÓҲ࣬¿ÉÒÔ·¢ÏÖ·¢ÆðÈý´ÎÎÕÊÖµÄSYN ±¨ÎÄ£¬Ò²¿ÉÒÔ·¢ÏÖһϵÁн»»¥µÄHTTP ±¨ÎÄ¡£
3¡¢·ÖÎöTCP ÐòÁÐ/Ó¦´ð±àºÅºÍÁ÷Á¿¿ØÖÆ
Ϊ·ÖÎö TCP ÐòºÅºÍÈ·ÈϺţ¬¿ÉÒÔ´Ó·Ö×éÁбíÖй۲죬Ҳ¿ÉÒÔµã»÷¡°Statitics/Flow Graph¡±£¬³öÏÖÈçͼ2 ËùʾµÄ±¾»úÓë·þÎñÆ÷Ö®¼äµÄͼ·ÖÎö½á¹û¡£
4¡¢·ÖÎöÓ¦ÓòãÄÚÈÝ
±¾ÊµÑéÖеÄÓ¦ÓòãÊÇ HTTP£¬¸ÃÐÒéµÄ¿É¿¿´«Êä»ùÓÚTCP µÃµ½µÄ¡£Í¨¹ý·ÖÎöTCP ±¨ÎÄÐòÁпÉÒԵõ½HTTP ´«ÊäµÄÄÚÈÝ¡£Îª´Ë£¬µã»÷TCP Èý´ÎÎÕÊÖÖ®¼äµÄµÚ4 ºÅ±¨ÎÄ£¬·¢ÏÖËüÊÇÒ»Ìõ´Ó±¾»úÏò·þÎñÆ÷·¢ËÍHTTP POST ÃüÁîµÄ±¨ÎÄ£¬ÇëÇóWeb ·þÎñÆ÷·¢ËÍÌØ¶¨µÄÒ³Ãæ¶ÔÏó¡£¶ÔÓÚºó¼Ì±¨ÎÄ£¬Ò²¿ÉÒÔ·¢ÏÖÒÔASCII Ã÷ÎÄ·¢Ë͵ÄÓ¦ÓòãÄÚÈÝ¡£
¶ÔÓÚ·ÖÎöÓ¦ÓòãÄÚÈÝ£¬Wireshark ÌṩÁËÒ»¸öºÜºÃµÄ¹¤¾ß¡£µã»÷¡°Analyze/Follow TCP Stream¡±£¬¿É´ò¿ªÈçͼ3 Ëùʾ½çÃæ£¬ÏÔʾÁ˸ÃTCP Á÷µÄÓ¦ÓòãÏà¹ØÐÅÏ¢¡£
24
5¡¢·ÖÎöTCP ÓµÈû¿ØÖÆ
µã»÷¡°Statistics/TCP Stream Graph/Throughput Gragh¡±£¬µÃµ½Èçͼ4 ËùʾµÄ½çÃæ¡£Í¼ÖеÄÿ¸öµã±íʾÔÚijʱ¿Ì¸ÃTCP Á¬½ÓµÄÍÌÍÂÁ¿¡£
Áù¡¢ÊµÑéÊý¾Ý¼Ç¼ºÍ½á¹û·ÖÎö
ͼ1 ÊìϤTCP ×Ù¼£Îļþ
ͼ2 ·ÖÎöTCP ÐòÁÐ/Ó¦´ð±àºÅºÍÁ÷Á¿¿ØÖÆ
25
ͼ3 ·ÖÎöÓ¦ÓòãÄÚÈÝ
ͼ4 ·ÖÎöTCP ÓµÈû¿ØÖÆ
26
Æß¡¢ÊµÑéÌå»á¡¢ÖÊÒɺͽ¨Òé
ËäÈ»WireSharkΪÎÒÃÇ·ÖÎöTCPÐÒé°üÌṩÁËÒ»¸öºÜºÃµÄ¿ÉÊÓ»¯»·¾³£¬µ«ÎÒÃÇѧϰTCPÐÒé²»ÄÜֻͣÁôÔÚËüÏÔʾµÄͳ¼ÆÊý¾ÝºÍ·ÖÎö½á¹ûÉÏÃæ£¬»¹ÒªÖªµÀËüΪʲôµÃ³öÕâÑùµÄ·ÖÎö½á¹û£¬´Ó¶øÉî¿ÌÀí½âTCPÐÒéʵÏÖ¿É¿¿Á¬½ÓºÍÓµÈû¿ØÖƵŤ×÷ÔÀí£¬½«ÀíÂÛºÍʵ¼ù½áºÏ£¬ÉѧϰЧ¹û¡£
27