์™€์ด์–ด์ƒคํฌ(Wireshark) ์‚ฌ์šฉ๋ฒ•2
Network

์™€์ด์–ด์ƒคํฌ(Wireshark) ์‚ฌ์šฉ๋ฒ•2

1.  Column ์„ธํŒ…

- ํŒจํ‚ท์„ ์›ํ•˜๋Š” Column ๊ธฐ์ค€์œผ๋กœ ์ •๋ ฌํ•˜์—ฌ ๋ณผ ์ˆ˜ ์žˆ์Œ

- ์ถ”๊ฐ€ํ•˜๊ณ  ์‹ถ์€ Column์ด ์žˆ์„ ๊ฒฝ์šฐ ์›ํ•˜๋Š” ํ•ญ๋ชฉ์—์„œ ์˜ค๋ฅธ์ชฝ ํด๋ฆญ ํ›„ [Apply as Column] ํด๋ฆญ

- ๋ฐ”๋กœ Column ์ถ”๊ฐ€ ํ™•์ธ ๊ฐ€๋Šฅ

- Column์˜ ์˜ค๋ฅธ์ชฝ ํด๋ฆญ ํ›„ ๋ณ€๊ฒฝ/์‚ญ์ œ ๊ฐ€๋Šฅ

2.  Filter ์„ธํŒ…

- ๋น„๊ต ์—ฐ์‚ฐ์ž

์—ฐ์‚ฐ์ž ์˜์–ด ํ‘œ๊ธฐ ์˜ˆ์ œ
== eq ip.src == 10.2.2.2
!= ne tcp.srcport != 80
> gt frame.time_relative > 1
< lt tcp.window_size < 1460
>= ge dns.count.answer >= 10
<= le ip.ttl <= 10
  contains http contains "GET"

- ๋…ผ๋ฆฌ ์—ฐ์‚ฐ์ž

์—ฐ์‚ฐ์ž ์˜์–ด ํ‘œ๊ธฐ ์˜ˆ์ œ
&& and ip.src == 10.2.2.2 and tcp.srcport != 80
|| or ip.src == 10.2.2.2 or tcp.srcport != 80
^^ xor ip.src == 10.2.2.2 xor tcp.srcport != 80
! not !(ip.src == 10.2.2.2) and tcp.srcport != 80

- ํ•„ํ„ฐ ์ž๋™์™„์„ฑ๋˜์–ด ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Œ

 

- ์ถ”๊ฐ€ํ•˜๊ณ  ์‹ถ์€ ํ•„ํ„ฐ๊ฐ€ ์žˆ์„ ๊ฒฝ์šฐ ์›ํ•˜๋Š” ํ•ญ๋ชฉ์—์„œ ์˜ค๋ฅธ์ชฝ ํด๋ฆญ ํ›„ [Apply as Filter] - [์›ํ•˜๋Š” ์กฐ๊ฑด] ํด๋ฆญ

- ๋ฐ”๋กœ ํ•„ํ„ฐ ์ ์šฉ ํ™•์ธ ๊ฐ€๋Šฅ

- ๋…ผ๋ฆฌ ์—ฐ์‚ฐ์ž๋ฅผ ํ†ตํ•˜์—ฌ ํ•„ํ„ฐ ํ™œ์šฉ ๊ฐ€๋Šฅ

3.  Stream ๋ณด๊ธฐ

- Stream์œผ๋กœ ๋ณด๊ณ  ์‹ถ์€ ํŒจํ‚ท ์„ ํƒํ•˜์—ฌ ์˜ค๋ฅธ์ชฝ ํด๋ฆญ ํ›„ [Follow] - [์›ํ•˜๋Š” Stream] ์„ ํƒ

- Stream ํ™•์ธ ๊ฐ€๋Šฅ(ํ”„๋กœํ† ์ฝœ์— ๋”ฐ๋ผ ๋‹ค๋ฅด๋ฉฐ ์•„๋ž˜ Stream์€ ์•”ํ˜ธํ™”๋˜์–ด ํ™•์ธ ๋ถˆ๊ฐ€)

- Stream ํŒจํ‚ท ํ™•์ธ ๊ฐ€๋Šฅ

4.  ๊ฐ Column๋“ค์˜ ์—ญํ• 

https://eunhyee.tistory.com/114?category=937476 

 

OSI ์ฐธ์กฐ ๋ชจ๋ธ(OSI 7 Layer)๊ณผ TCP/IP

1. OSI ์ฐธ์กฐ ๋ชจ๋ธ(OSI 7 Layer) OSI 7 ๊ณ„์ธต ๊ณ„์ธต ๊ณ„์ธต ์ด๋ฆ„ ์—ญํ•  ๋„คํŠธ์›Œํฌ ์žฅ๋น„ ์ฃผ์š” ํ”„๋กœํ† ์ฝœ 7 ์‘์šฉ ๊ณ„์ธต ์ธํ„ฐํŽ˜์ด์Šค์˜ ์—ญํ• ์„ ํ•˜์—ฌ ์‚ฌ์šฉ์ž๊ฐ€ ์ปดํ“จํ„ฐ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์›น ์„œํ•‘, ํŒŒ์ผ ์ „์†ก, ๋ฉ”์ผ ๋“ฑ์˜ ์„œ๋น„

eunhyee.tistory.com

 

โ—€ ์™€์ด์–ด์ƒคํฌ(Wireshark) ์‚ฌ์šฉ๋ฒ•1

https://eunhyee.tistory.com/181?category=937476 

 

์™€์ด์–ด์ƒคํฌ(Wireshark) ์‚ฌ์šฉ๋ฒ•1

1. ์™€์ด์–ด์ƒคํฌ๋ž€?! - ์˜คํ”ˆ์†Œ์Šค ์†Œํ”„ํŠธ์›จ์–ด ํ”„๋กœ๊ทธ๋žจ - ์„ธ๊ณ„์—์„œ ๊ฐ€์žฅ ๋งŽ์ด ์‚ฌ์šฉํ•˜๋Š” ๋„คํŠธ์›Œํฌ ๋ถ„์„ ๋„๊ตฌ ๋ฐ ๋ณด์•ˆ ๋„๊ตฌ - ์œ /๋ฌด์„  ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ์—์„œ ๋„คํŠธ์›Œํฌ ํ”„๋ ˆ์ž„์„ ์ˆ˜์ง‘ํ•˜์—ฌ ๋„คํŠธ์›Œํฌ ๋ฌธ์ œ์ ‘

eunhyee.tistory.com

 

'Network' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

ARP(Address Resolution Protocol)  (0) 2021.05.30
STP(Spanning Tree Protocol)  (0) 2021.05.30
์™€์ด์–ด์ƒคํฌ(Wireshark) ์‚ฌ์šฉ๋ฒ•1  (0) 2021.05.25
์žฅ๋น„ ์„ธํŒ… ๋ฐ ์ ‘์†  (0) 2021.05.19
EtherChannel  (1) 2021.05.17