官术网_书友最值得收藏!

Isolating conversations of interest

After you have completed a packet capture and saved a bulk capture file, you'll be with an almost overwhelming number of packets of various types and addresses in the Packet List pane. It's now time to par this down to just the packets that pertain to the analysis task at hand.

The idea is to progressively eliminate unrelated packets; analyze the pertinent conversations looking for anomalies; and again progressively filter, measure, and analyze packet flow and application behavior until you have discovered and can document the root cause of the issue.

There are two basic ways to isolate and inspect packets and conversations of interest, and you'll likely use both of the following methods in most of your analysis activities:

  • Conversations: This window creates a list of conversation pairs by MAC or IP address and/or TCP/UDP ports that can be sorted. It displays filters that will isolate and display only the selected conversation packets can be quickly applied from this window.
  • Display Filters: These filters are based on MAC or IP addresses and/or protocol-specific fields that limit the packets displayed in the Packet List pane.

We'll discuss each of these methods in the following sections.

主站蜘蛛池模板: 温宿县| 台中市| 崇文区| 西宁市| 乡城县| 池州市| 马鞍山市| 敦化市| 吉安市| 胶南市| 绥化市| 贡嘎县| 博爱县| 吉木乃县| 天台县| 英德市| 黔江区| 通城县| 乐昌市| 邵阳县| 龙海市| 潞西市| 沙雅县| 甘孜县| 莱阳市| 龙口市| 苗栗县| 竹溪县| 西藏| 高安市| 广宗县| 平顶山市| 陵川县| 昭平县| 靖宇县| 洪泽县| 塔河县| 岳阳县| 遂平县| 高碑店市| 全南县|