官术网_书友最值得收藏!

How Wireshark works

Wireshark collects network traffic from the wire through the computer's network interface, running in promiscuous mode (if needed), to inspect and display information related to protocols, IP addresses, ports, headers, and packet length. The following diagram is an illustration of how all the elements work together to display packet-level information to the user (source: https://www.wireshark.org):

Wireshark comes with the Winpcap/libcap driver, which enables NIC to the run in promiscuous mode; the only time you don't have to sniff in promiscuous mode is when the packets are directly, intentionally destined/generated to and/or from your device.

On operating systems, you should have privileges to run Wireshark. There are three processes that every protocol analyzer follows: collect, convert, and analyze. These are described as follows:

  • Collect: Choose an interface to listen to traffic and capture network packets.
  • Convert: Increase the readability of non-human-readable data. Packets are converted to easily understood information through a GUI.
  • Analyze: Analyze network traffic pertaining to the packets, protocols, raw data and more through the usage of statistical and graphical features.

As discussed in the previous chapter, protocols are the set of rules and regulations that govern the process of communication between two network devices and control the environment under which they operate.

主站蜘蛛池模板: 柘荣县| 含山县| 阜平县| 张家界市| 含山县| 淳安县| 南雄市| 武安市| 兴和县| 济南市| 张家界市| 杂多县| 孟村| 宝应县| 龙胜| 浦北县| 邵阳县| 新乐市| 凤台县| 太湖县| 惠州市| 石门县| 固始县| 华安县| 清流县| 龙州县| 昆山市| 达尔| 三亚市| 广水市| 满洲里市| 隆化县| 和平县| 亳州市| 伊宁市| 会昌县| 米脂县| 邹平县| 比如县| 兰溪市| 河源市|