摘要
捕获网络数据包可以用来检测并分析网络面临的安全性威胁,网络数据包的捕获广泛应用于IP网络性能测量、流量分析、用户计费、网络入侵检测、网络协议分析及口令拦截等多种场合。介绍了以太网数据包的捕获机制,并在此基础上采用Linux的Lipcap和Socket两种方法,讨论了网络数据包捕获工具的开发过程,同时给出TCP/IP首部的提取方法,以便对捕获的数据作进一步的分析与处理。
Packet capture is used to detect and analyze network on the aspect of security threat, whereas packet capture is widely applied in several occasions such as capability measure, flow analyse, charge statistic, intrusion detection, protocol analyse and password intercepting etc. Packet capture mechanism is introduced, and then lipcap and socket methods are adopted, the development and implement of network packet capture is discussed, and pick-up way of the header of TCP/IP is given, in order to analyse and deal with the captured packet further.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第8期1834-1836,共3页
Computer Engineering and Design