请输入您要查询的百科知识:

 

词条 Packet analyzer
释义

  1. Capabilities

  2. Uses

  3. Notable packet analyzers

  4. See also

  5. Notes

  6. References

  7. External links

{{Short description|Computer network equipment or software that analyzes network traffic}}{{Use mdy dates|date = March 2019}}{{refimprove |date=March 2013}}{{Use American English|date=March 2015}}

A packet analyzer (also known as a packet sniffer) is a computer program or piece of computer hardware that can intercept and log traffic that passes over a digital network or part of a network.[1] Packet capture is the process of intercepting and logging traffic. As data streams flow across the network, the sniffer captures each packet and, if needed, decodes the packet's raw data, showing the values of various fields in the packet, and analyzes its content according to the appropriate RFC or other specifications.

A packet analyzer used for intercepting traffic on wireless networks is known as a wireless analyzer or WiFi analyzer. A packet analyzer can also be referred to as a network analyzer or protocol analyzer though these terms also have other meanings.

Capabilities

On wired shared medias networks, such as Ethernet, Token Ring, and FDDI networks, depending on the network structure (hub or switch),[2]{{efn|Some methods avoid traffic narrowing by switches to gain access to traffic from other systems on the network (e.g., ARP spoofing).}} it may be possible to capture all traffic on the network from a single machine on the network. On modern networks, traffic can be captured using a network switch with a so-called monitoring port that mirrors all packets that pass through designated ports of the switch. A network tap is an even more reliable solution than to use a monitoring port, since taps are less likely to drop packets during high traffic load.

On wireless LANs, traffic can be captured on one channel at a time, or by using multiple adapters, on several channels simultaneously.

On wired broadcast and wireless LANs, to capture unicast traffic between other machines, the network adapter capturing the traffic must be in promiscuous mode. On wireless LANs, even if the adapter is in promiscuous mode, packets not for the service set the adapter is configured for are usually ignored. To see those packets, the adapter must be in monitor mode.{{Citation needed|date=January 2012}} No special provisions are required to capture multicast traffic to a multicast group the packet analyzer is already monitoring, or broadcast traffic.

When traffic is captured, either the entire contents of packets are recorded, or just the headers are recorded. Recording just headers reduces storage requirements, and avoids some legal issues, yet often provides sufficient information to diagnose problems.

Captured information is decoded from raw digital form into a human-readable format that lets users easily review exchanged information. Protocol analyzers vary in their abilities to display data in multiple views, automatically detect errors, determine root causes of errors, generate timing diagrams, reconstruct TCP and UDP data streams, etc.{{Citation needed|date=January 2012}}

Some protocol analyzers can also generate traffic and thus act as the reference device. These can act as protocol testers. Such testers generate protocol-correct traffic for functional testing, and may also have the ability to deliberately introduce errors to test the DUT's ability to handle errors.{{Citation needed|date=January 2012}}

Protocol analyzers can also be hardware-based, either in probe format or, as is increasingly common, combined with a disk array. These devices record packets (or a slice of the packet) to a disk array. This allows historical forensic analysis of packets without users having to recreate any fault.{{Citation needed|date=January 2012}}

Uses

Packet sniffers can:{{Citation needed|date=January 2012}}

  • Analyze network problems
  • Detect network intrusion attempts
  • Detect network misuse by internal and external users
  • Documenting regulatory compliance through logging all perimeter and endpoint traffic
  • Gain information for effecting a network intrusion
  • Isolate exploited systems
  • Monitor WAN bandwidth utilization
  • Monitor network usage (including internal and external users and systems)
  • Monitor data-in-motion
  • Monitor WAN and endpoint security status
  • Gather and report network statistics
  • Filter suspect content from network traffic
  • Serve as primary data source for day-to-day network monitoring and management
  • Spy on other network users and collect sensitive information such as login details or users cookies (depending on any content encryption methods that may be in use)
  • Reverse engineer proprietary protocols used over the network
  • Debug client/server communications
  • Debug network protocol implementations
  • Verify adds, moves and changes
  • Verify internal control system effectiveness (firewalls, access control, Web filter, spam filter, proxy)

Packet capture can be used to fulfill a warrant from a law enforcement agency (LEA) to produce all network traffic generated by an individual. Internet service providers and VoIP providers in the United States must comply with CALEA (Communications Assistance for Law Enforcement Act) regulations. Using packet capture and storage, telecommunications carriers can provide the legally required secure and separate access to targeted network traffic and are able to use the same device for internal security purposes. Collecting data from a carrier system without a warrant is illegal due to laws about interception. By using end-to-end encryption, communications can be kept confidential from telecommunication carriers and legal authorities.

Notable packet analyzers

{{Mainlist|Comparison of packet analyzers}}{{div col|colwidth=20em}}
  • Capsa Network Analyzer
  • Charles Web Debugging Proxy
  • Carnivore (FBI)
  • CommView
  • dSniff
  • EndaceProbe Analytics Platform by Endace
  • ettercap
  • Fiddler
  • Kismet
  • Lanmeter
  • Microsoft Network Monitor
  • NarusInsight
  • NetScout Systems nGenius Infinistream
  • ngrep, Network Grep
  • OmniPeek, Omnipliance by Savvius
  • SkyGrabber
  • snoop
  • tcpdump
  • Observer Analyzer
  • Wireshark (formerly known as Ethereal)
  • Xplico Open source Network Forensic Analysis Tool
{{div col end}}

See also

  • Bus analyzer
  • Logic analyzer
  • Network detector
  • Network intrusion detection system
  • Network tap
  • Packet generation model
  • pcap
  • Signals intelligence

Notes

{{notelist}}

References

1. ^{{cite book|title=Law of Internet Security and Privacy|author=Kevin J. Connolly|pages=131|year=2003|isbn=978-0-7355-4273-0|publisher=Aspen Publishers}}
2. ^{{Cite web |title = Network Segment Definition |url = http://www.linfo.org/network_segment.html |website = www.linfo.org |access-date = 2016-01-14}}

External links

{{Commons category|Computer data network analyzers}}{{Wikiversity | Packet analyzer}}
  • {{dmoz|Computers/Software/Networking/Network_Performance/Protocol_Analyzers/|Protocol Analyzers}}
  • Multi-Tap Network Packet Capture
{{Authority control}}

5 : Network analyzers|Packets (information technology)|Wireless networking|Computer network security|Deep packet capture

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/11/12 11:01:57