官术网_书友最值得收藏!

Isolating conversations of interest

After you have completed a packet capture and saved a bulk capture file, you'll be with an almost overwhelming number of packets of various types and addresses in the Packet List pane. It's now time to par this down to just the packets that pertain to the analysis task at hand.

The idea is to progressively eliminate unrelated packets; analyze the pertinent conversations looking for anomalies; and again progressively filter, measure, and analyze packet flow and application behavior until you have discovered and can document the root cause of the issue.

There are two basic ways to isolate and inspect packets and conversations of interest, and you'll likely use both of the following methods in most of your analysis activities:

  • Conversations: This window creates a list of conversation pairs by MAC or IP address and/or TCP/UDP ports that can be sorted. It displays filters that will isolate and display only the selected conversation packets can be quickly applied from this window.
  • Display Filters: These filters are based on MAC or IP addresses and/or protocol-specific fields that limit the packets displayed in the Packet List pane.

We'll discuss each of these methods in the following sections.

主站蜘蛛池模板: 新营市| 隆德县| 齐河县| 凌源市| 临高县| 页游| 哈密市| 阳高县| 涞源县| 建水县| 广安市| 萨迦县| 长沙市| 马龙县| 内黄县| 阜南县| 玉屏| 甘谷县| 黄山市| 兴隆县| 乌鲁木齐市| 泌阳县| 乌兰县| 乌拉特后旗| 教育| 蒙山县| 濮阳市| 五华县| 南昌市| 闵行区| 麟游县| 泰兴市| 昌吉市| 红原县| 疏勒县| 太原市| 诏安县| 德昌县| 丰城市| 徐州市| 东阳市|