һվʽѧϰWireshark£¨Èý£©£ºÓ¦ÓÃWiresharkIOͼÐι¤¾ß·ÖÎöÊý¾ÝÁ÷
2015-11-23 09:45:06 | À´Ô´£ºÍæת°ï»á | Ͷ¸å£ºØýÃû | ±à¼­£ºÐ¡¿Â

Ô­±êÌ⣺һվʽѧϰWireshark£¨Èý£©£ºÓ¦ÓÃWiresharkIOͼÐι¤¾ß·ÖÎöÊý¾ÝÁ÷

»ù±¾IO Graphs:

IO graphsÊÇÒ»¸ö·Ç³£ºÃÓõŤ¾ß¡£»ù±¾µÄWireshark IO graph»áÏÔʾץ°üÎļþÖеÄÕûÌåÁ÷Á¿Çé¿ö£¬Í¨³£ÊÇÒÔÿÃëΪµ¥Î»£¨±¨ÎÄÊý»ò×Ö½ÚÊý£©¡£Ä¬ÈÏXÖáʱ¼ä¼ä¸ôÊÇ1Ã룬YÖáÊÇÿһʱ¼ä¼ä¸ôµÄ±¨ÎÄÊý¡£Èç¹ûÏëÒª²é¿´Ã¿ÃëbitÊý»òbyteÊý£¬µã»÷¡°Unit¡±£¬ÔÚ¡°Y Axis¡±ÏÂÀ­ÁбíÖÐÑ¡ÔñÏëÒª²é¿´µÄÄÚÈÝ¡£ÕâÊÇÒ»ÖÖ»ù±¾µÄÓ¦Ó㬶ÔÓڲ鿴Á÷Á¿ÖеIJ¨·å/²¨¹ÈºÜÓаïÖú¡£Òª½øÒ»²½²é¿´£¬µã»÷ͼÐÎÖеÄÈÎÒâµã¾Í»á¿´µ½±¨ÎĵÄϸ½Ú¡£

ΪÁ˽²½â·½±ã£¬µã»÷ʾÀý±¨ÎÄ°ü£¬»òÓÃ×Ô¼ºµÄwiresharkµã»÷Statistics ¨C IO Graphs¡£Õâ¸ö×¥°üÊÇHTTPÔ¤¸æÓöµ½±¨ÎĶªÊ§µÄÇé¿ö¡£

×¢Ò⣺¹ýÂËÌõ¼þΪ¿Õ£¬´ËͼÐÎÏÔʾËùÓÐÁ÷Á¿¡£

Õâ¸öĬÈÏÌõ¼þϵÄÏÔʾÔÚ´ó¶àÊýtroubleshootingÖв¢²»ÊǷdz£ÓÐÓ᣽«YÖá¸ÄΪbits/tickÕâÑù¾Í¿ÉÒÔ¿´µ½Ã¿ÃëµÄÁ÷Á¿¡£´ÓÕâÕÅͼ¿ÉÒÔ¿´µ½·åÖµËÙÂÊÊÇ300kbps×óÓÒ¡£Èç¹ûÄã¿´µ½ÓÐЩµØ·½Á÷Á¿Ï½µÎªÁ㣬ÄÇ¿ÉÄÜÊÇÒ»¸ö³öÎÊÌâµÄµã¡£Õâ¸öÎÊÌâÔÚͼÉϺܺ÷¢ÏÖ£¬µ«ÔÚ¿´±¨ÎÄÁбíʱ¿ÉÄܲ»ÄÇôÃ÷ÏÔ¡£

¹ýÂË£º

ÿһ¸öͼÐζ¼¿ÉÒÔÓ¦ÓÃÒ»¸ö¹ýÂËÌõ¼þ¡£ÕâÀï´´½¨Á½¸ö²»Í¬µÄgraph£¬Ò»¸öHTTPÒ»¸öICMP¡£¿ÉÒÔ¿´µ½¹ýÂËÌõ¼þÖÐGraph 1ʹÓá°http¡±Graph 2ʹÓá°icmp¡±¡£Í¼ÖпÉÒÔ¿´µ½ºìÉ«ICMPÁ÷Á¿ÖÐÓÐЩ¼ä϶£¬½øÒ»²½·ÖÎö¡£

´´½¨Á½¸öͼÐΣ¬Ò»¸öÏÔʾICMP Echo£¨Type=8£©Ò»¸öÏÔʾICMP Reply£¨Type=0£©¡£Õý³£Çé¿ö϶ÔÓÚÿһ¸öechoÇëÇó»áÓÐÒ»¸öÁ¬ÐøµÄreply¡£ÕâÀïµÄÇé¿öÊÇ£º

¿ÉÒÔ¿´µ½ºìÉ«Âö³åÏß(icmp type==0 ¨C ICMP Reply)ÖмäÓмä϶£¬¶øÕûÕÅͼÖÐICMPÇëÇó±£³ÖÁ¬Ðø¡£ÕâÒâζ×ÅÓÐЩreplyûÓнÓÊÕµ½¡£ÕâÊÇÓÉÓÚ±¨ÎĶªÊ§µ¼ÖµÄreply drop¡£CLIÖп´µ½µÄpingÐÅÏ¢ÈçÏ£º

³£ÓÃÅÅ´í¹ýÂËÌõ¼þ:

¶ÔÓÚÅŲéÍøÂçÑÓʱ/Ó¦ÓÃÎÊÌâÓÐһЩ¹ýÂËÌõ¼þÊǷdz£ÓÐÓõģº

tcp.analysis.lost_segment£º±íÃ÷ÒѾ­ÔÚ×¥°üÖп´µ½²»Á¬ÐøµÄÐòÁкš£±¨ÎĶªÊ§»áÔì³ÉÖظ´µÄACK£¬Õâ»áµ¼ÖÂÖØ´«¡£

tcp.analysis.duplicate_ack£ºÏÔʾ±»È·ÈϹý²»Ö¹Ò»´ÎµÄ±¨ÎÄ¡£´óÁ¹µÄÖظ´ACKÊÇTCP¶ËµãÖ®¼ä¸ßÑÓʱµÄ¼£Ïó¡£

tcp.analysis.retransmission£ºÏÔʾץ°üÖеÄËùÓÐÖØ´«¡£Èç¹ûÖØ´«´ÎÊý²»¶àµÄ»°»¹ÊÇÕý³£µÄ£¬¹ý¶àÖØ´«¿ÉÄÜÓÐÎÊÌâ¡£Õâͨ³£Òâζ×ÅÓ¦ÓÃÐÔÄÜ»ºÂýºÍ/»òÓû§±¨ÎĶªÊ§¡£

tcp.analysis.window_update£º½«´«Êä¹ý³ÌÖеÄTCP window´óСͼÐλ¯¡£Èç¹û¿´µ½´°¿Ú´óСϽµÎªÁ㣬ÕâÒâζ×Å·¢ËÍ·½ÒѾ­Í˳öÁË£¬²¢µÈ´ý½ÓÊÕ·½È·ÈÏËùÓÐÒÑ´«ËÍÊý¾Ý¡£Õâ¿ÉÄܱíÃ÷½ÓÊÕ¶ËÒѾ­²»¿°ÖظºÁË¡£

tcp.analysis.bytes_in_flight£ºÄ³Ò»Ê±¼äµãÍøÂçÉÏδȷÈÏ×Ö½ÚÊý¡£Î´È·ÈÏ×Ö½ÚÊý²»Äܳ¬¹ýÄãµÄTCP´°¿Ú´óС£¨¶¨ÒåÓÚ×î³õ3´ËTCPÎÕÊÖ£©£¬ÎªÁË×î´ó»¯ÍÌÍÂÁ¿ÄãÏëÒª»ñµÃ¾¡¿ÉÄܽӽüTCP´°¿Ú´óС¡£Èç¹û¿´µ½Á¬ÐøµÍÓÚTCP´°¿Ú´óС£¬¿ÉÄÜÒâζ×ű¨ÎĶªÊ§»ò·¾¶ÉÏÆäËûÓ°ÏìÍÌÍÂÁ¿µÄÎÊÌâ¡£

tcp.analysis.ack_rtt£ººâÁ¿×¥È¡µÄTCP±¨ÎÄÓëÏàÓ¦µÄACK¡£Èç¹ûÕâһʱ¼ä¼ä¸ô±È½Ï³¤ÄÇ¿ÉÄܱíʾijÖÖÀàÐ͵ÄÍøÂçÑÓʱ£¨±¨ÎĶªÊ§£¬ÓµÈû£¬µÈµÈ£©¡£

ÔÚ×¥°üÖÐÓ¦ÓÃÒÔÉÏһЩ¹ýÂËÌõ¼þ£º

×¢Ò⣺Graph 1ÊÇHTTP×ÜÌåÁ÷Á¿£¬ÏÔʾÐÎʽΪpackets/tick£¬Ê±¼ä¼ä¸ô1Ãë¡£Graph 2ÊÇTCP¶ªÊ§±¨ÎÄƬ¶Î¡£Graph 3ÊÇTCPÖظ´ACK¡£Graph 4ÊÇTCPÖØ´«¡£

´ÓÕâÕÅͼ¿ÉÒÔ¿´µ½£ºÏà±ÈÓÚÕûÌåHTTPÁ÷Á¿£¬ÓкܶàÊýÁ¿µÄÖØ´«ÒÔ¼°Öظ´ACK¡£´ÓÕâÕÅͼÖУ¬¿ÉÒÔ¿´µ½ÕâЩʼþ·¢ÉúµÄʱ¼äµã£¬ÒÔ¼°ÔÚÕûÌåÁ÷Á¿ÖÐËùÕ¼µÄ±ÈÀý¡£

º¯Êý:

IO GraphsÓÐÁù¸ö¿ÉÓú¯Êý£ºSUM,MIN, AVG, MAX, COUNT, LOAD¡£

MIN( ), AVG( ), MAX( )

Ê×ÏÈ¿´Ò»ÏÂÖ¡Ö®¼äµÄ×îС£¬Æ½¾ùºÍ×î´óʱ¼ä£¬Õâ¶ÔÓڲ鿴֡/±¨ÎÄÖ®¼äµÄÑÓʱ·Ç³£ÓÐÓá£ÎÒÃÇ¿ÉÒÔ½«ÕâЩº¯Êý½áºÏ¡°frame.time_delta¡±¹ýÂËÌõ¼þ¿´Çå³þÖ¡ÑÓʱ£¬²¢Ê¹µÃÍù·µÑÓʱ¸üΪÃ÷ÏÔ¡£Èç¹û×¥°üÎļþÖаüº¬²»Í¬Ö÷»úÖ®¼äµÄ¶à¸ö»á»°£¬¶øÖ»ÏëÖªµÀÆäÖÐÒ»¸öpair£¬¿É½«¡°frame.time_delta¡±½áºÏÔ´ºÍÄ¿±êÖ÷»úÌõ¼þÈç¡°ip.addr==x.x.x.x&&ip.addr==y.y.y.y¡±¡£ÈçÏÂͼËùʾ£º

ÎÒÃÇ×öÁËÒÔϲ½Ö裺

  • ½«YÖáÉèÖÃΪ¡°Advanced¡±£¬ÈÃCaculationÓò¿É¼û¡£²»×öÕâÒ»²½¾Í¿´²»µ½¼ÆËãÑ¡Ïî¡£
  • XÖáʱ¼ä¼ä¸ô1Ã룬ËùÒÔÿ¸öÖù״ͼ´ú±í1Ãë¼ä¸ôµÄ¼ÆËã½á¹û¡£
  • ¹ýÂ˳öÁ½¸öÌض¨IPµØÖ·µÄHTTP»á»°£¬Ê¹ÓÃÌõ¼þ£º¡°(ip.addr==192.168.1.4&&ip.addr==128.173.87.169) && http¡±¡£
  • ʹÓÃ3¸ö²»Í¬µÄgraph£¬·Ö±ð¼ÆËãMin(), Avg(), Max()¡£
  • ¶Ôÿһ¸ö¼ÆËã½á¹ûÓ¦ÓÃÌõ¼þ¡°frame.time_delta¡±£¬½«styleÉèÖóɡ°FBar¡±£¬ÏÔʾЧ¹û×î¼Ñ¡£

´ÓÉÏͼ¿É¼û£¬ÔÚµÚ106ÃëʱÊý¾ÝÁ÷µÄMAX frame.delta_time´ïµ½0.7Ã룬ÕâÊÇÒ»¸öÑÏÖØÑÓʱ²¢ÇÒµ¼ÖÂÁ˱¨ÎĶªÊ§¡£Èç¹ûÏëÒªÉîÈëÑо¿£¬Ö»ÐèÒªµã»÷ͼÖÐÕâÒ»µã£¬¾Í»áÌøתÖÁÏàÓ¦Ö¡¡£¶ÔÓ¦ÓÚ±¾Àý×¥°üÎļþÖеÚ1003¸ö±¨ÎÄ¡£Èç¹ûÄã¿´¼ûÖ¡Ö®¼äƽ¾ùÑÓʱÏà¶Ô½ÏµÍµ«Í»È»Ä³Ò»µãÑÓʱºÜ³¤£¬¿Éµã»÷ÕâÒ»Ö¡£¬¿´¿´Õâһʱ¼äµã¾¿¾¹·¢ÉúÁËʲô¡£

Count( )

´Ëº¯Êý¼ÆËãʱ¼ä¼ä¸ôÄÚʼþ·¢ÉúµÄ´ÎÊý£¬Ôڲ鿴TCP·ÖÎö±êʶ·ûʱºÜÓÐÓã¬ÀýÈçÖØ´«¡£ÀýͼÈçÏ£º

Sum( )

¸Ãº¯Êýͳ¼ÆʼþµÄÀÛ¼ÓÖµ¡£ÓÐÁ½ÖÖ³£¼ûµÄÓÃÀýÊÇ¿´ÔÚ²¶»ñTCPÊý¾ÝÁ¿£¬ÒÔ¼°¼ì²éTCPÐòÁкš£ÈÃÎÒÃÇ¿´¿´µÚÒ»¸öTCP³¤¶ÈµÄÀý×Ó¡£´´½¨Á½¸öͼ£¬Ò»¸öʹÓÿͻ§¶ËIP 192.168.1.4ΪԴ£¬ÁíÒ»¸öʹÓÿͻ§¶ËIP×÷Ϊһ¸öÄ¿µÄµØÖ·¡£Ã¿¸öͼÎÒÃǽ«sum()¹¦ÄܽáºÏtcp.len¹ýÂËÌõ¼þ¡£²ð·Ö³ÉÁ½¸ö²»Í¬µÄͼÎÒÃǾͿÉÒÔ¿´µ½ÔÚÒ»¸öµ¥Ò»µÄ·½ÏòÒƶ¯µÄÊý¾ÝÁ¿¡£

´Óͼ±íÖÐÎÒÃÇ¿ÉÒÔ¿´µ½£¬·¢Ë͵½¿Í»§¶ËµÄÊý¾ÝÁ¿£¨IP.DST = = 192.168.1.4¹ýÂËÌõ¼þ£©±ÈÀ´×Ô¿Í»§¶ËµÄÊý¾ÝÁ¿Òª¸ß¡£ÔÚͼÖкìÉ«±íʾ¡£ºÚÌõÏÔʾ´Ó¿Í»§¶Ëµ½·þÎñÆ÷µÄÊý¾Ý£¬Ïà¶ÔÊý¾ÝÁ¿ºÜС¡£ÕâÊÇÓеÀÀíµÄ£¬ÒòΪ¿Í»§Ö»ÊÇÇëÇóÎļþºÍÊÕµ½Ö®ºó·¢ËÍÈ·ÈÏÊý¾Ý£¬¶ø·þÎñÆ÷·¢ËÍ´óÎļþ¡£ºÜÖØÒªµÄÒ»µãÊÇ£¬Èç¹ûÄã½»»»ÁËͼµÄ˳Ðò£¬°Ñ¿Í»§¶ËµÄIP×÷Ϊͼ1µÄÄ¿±êµØÖ·£¬²¢ÇÒ¿Í»§¶ËIP×÷Ϊͼ2µÄÔ´µØÖ·£¬²ÉÓÃÁËFBARµÄʱºò¿ÉÄÜ¿´²»µ½ÕýÈ·µÄÊý¾ÝÏÔʾ¡£ÒòΪͼ±àºÅÔ½µÍ±íʾÔÚǰ̨ÏÔʾ£¬¿ÉÄܻḲ¸Ç½Ï¸ßͼºÅ¡£

ÏÖÔÚÈÃÎÒÃÇ¿´Ò»ÏÂͬһ¸öÊý¾Ý°ü¶ªÊ§ºÍÑÓ³ÙµÄTCPÐòÁкš£

¿ÉÒÔÔÚͼÖп´µ½Èô¸É·åÖµºÍϽµ£¬±íʾTCP´«ÊäÓÐÎÊÌâ¡£ÓëÕý³£TCP±¨ÎıȽϣº

ÕâÕÅͼ¿ÉÒÔ¿´µ½TCPÐòÁкÅÏ൱Îȶ¨µØÔö¼Ó£¬±íʾ´«ÊäƽÎÈ£¬Ã»Óйý¶àÖØ´«»ò¶ª°ü¡£

±¾ÎÄϵÁÐĿ¼£º
  • һվʽѧϰWireshark£¨Ò»£©£ºWireshark»ù±¾Ó÷¨
  • һվʽѧϰWireshark£¨¶þ£©£ºÓ¦ÓÃWireshark¹Û²ì»ù±¾ÍøÂçЭÒé
  • һվʽѧϰWireshark£¨Èý£©£ºÓ¦ÓÃWireshark IOͼÐι¤¾ß·ÖÎöÊý¾ÝÁ÷
  • һվʽѧϰWireshark£¨ËÄ£©£ºÍøÂçÐÔÄÜÅŲéÖ®TCPÖØ´«ÓëÖظ´ACK
  • һվʽѧϰWireshark£¨Î壩£ºTCP´°¿ÚÓëÓµÈû´¦Àí
  • һվʽѧϰWireshark£¨Áù£©£º¾Ñ»÷ÍøÂç¸ßÑÓʱµã
  • һվʽѧϰWireshark£¨Æߣ©£ºStatisticsͳ¼Æ¹¤¾ß¹¦ÄÜÏê½âÓëÓ¦ÓÃ
  • һվʽѧϰWireshark£¨°Ë£©£ºÓ¦ÓÃWireshark¹ýÂËÌõ¼þץȡÌض¨Êý¾ÝÁ÷

tags£º

ÉÏһƪ  ÏÂһƪ

Ïà¹Ø£º

Wireshark»ù±¾½éÉܺÍѧϰTCPÈý´ÎÎÕÊÖ

ÕâƪÎÄÕ½éÉÜÁíÒ»¸öºÃÓõÄ×¥°ü¹¤¾ß Wireshark£¬ÓÃÀ´»ñÈ¡ÍøÂçÊý¾Ý·â°ü£¬°üÀ¨ HTTP¡¢TCP¡¢UDP µÈÍøÂçЭÒé°ü¡£

°Ñ·ÏÆúµÄ¸ß¼Ü±ä³É¹«Ô°£¬Å¦Ô¼Ö®ºóÓÖÓÐÁËϤÄá

¼ÌŦԼ¸ßÏß¹«Ô°ºó£¬Ï¤ÄáÒ²ÓÐÁË×Ô¼ºµÄ¸ßÏß¹«Ô°£¬½«¹ýȥͨÍùϤÄả¸ÛÏÖÔÚÒѾ­·ÏÆúµÄ Ultimo »õÔËÌúµÀº½Ï߸ÄÔì

ËûÏ£Íû×Ô¼º×ö³öµÄÿ¼þÊ×Êζ¼ÄܳÉΪ´«ÊÀÖ®±¦

±¾ÎÄÓÉ Coolhunting ÊÚȨ¡¶ºÃÆæÐÄÈÕ±¨¡··¢²¼£¬¼´Ê¹ÎÒÃÇÔÊÐíÁËÒ²²»ÐíתÔØ¡£ Íþ¶ûÊ¿³öÉú£¬ÐÂÎ÷À¼³¤´ó£¬Ä¿Ç°ÔÚ

˭˵½¡¿µ²Í¾ÍÊǹû֭ɳÀ­£¿Õâ¸ö¹Ý×Ó×öµÄ±£Ö¤ÄãÓÐʳÓû

ÔÚŦԼÂü¹þ¶Ù£¬½ü¼¸ÄêÓиöÁ¬Ëø²ÍÌü Dig Inn ºÜÊÜ»¶Ó­£¬×öµÄÒ²ËãÊÇ¿ì²Í£¬ÏñÄãÔÚ¹¤×÷ÈÕÎç²Íʱ¼ä¡¢½¡ÉíÇ°¡­¡­

Èç¹ûÄãÃÔÁµÃÀ¾çÖ÷½ÇµÄ´ò°ç£¬Ëü¿ÉÒÔ°ïÖúÄãÕÒµ½ÄÇЩÒ·þ

ÄãÊÇ·ñÓÐÔø¾­ÃÔÁµ¹ýÃÀ¾çÈËÎïµÄ¾­µäÔìÐÍ£¿ËûÃÇƯÁÁµÄÒ·þÓÐûÓÐÈÃÄãÃÈÉú¹ý¡°°¡£¬ÎÒÒ²ÏëÒªÒ»¼þ¡±µÄÄîÍ·£¿ Èç

ÈËÀàÔõÑù»á¸Ðµ½ÐÒ¸££¿´óÄÔ¶´Éè¼ÆʦÓúü¸Äêı»®ÁËÒ»¸öÕ¹

Stefan Sagmeister ÊdzöÉúÓڰµØÀûµÄƽÃæÉè¼Æʦ£¬¸ü¹ãΪÈËÖªµÄÖÐÎÄÃû×ÖÊÇÊ©µÂÃ÷¡£ËûÔø¾­Îª¹öʯÀÖ¶Ó¡¢Â¬&mi

ÕâÌõµØÌúºá´©³¤½­Ï¼¸Ê®Ã×£¬¿É¾ÍÊǸоõ²»µ½ÉÏÏÂÆÂ

¹ØÓÚƶȸù¾ÝÎÒ¹úµØÌúÉè¼Æ¹æ·¶µÄÒªÇó£¬ÕýÏßƶȲ»´óÓÚ 3.0%£¨±ê×¼µ¥Î»Ó¦ÎªÇ§·ÖÖÆ£¬Ò԰ٷֺŻ»Ëã±í´ï£©£¬ÌØÊâ

ÖйúÌØÉ«¡¸°Ñʺ°ÑÄò¡¹£¬ÕâЩΣº¦ÄãÖªµÀÂð£¿

ÔÚÈçºÎÑøº¢×ÓµÄÎÊÌâÉÏ£¬ÎҺ͸¸Ä¸Ò»±²ÓÐ×Ų»ÉÙ·ÖÆç¡£×î´óµÄ·ÖÆçÖ®Ò»£¬ÊǸò»¸Ã¸øº¢×Ó°ÑÄò¡£Ð¡ÃȵÄÀÑÒ¯¾õµÃ£¬

СѧÁùÄ꼶µÄÎÒ£¬Í½ÊÖÔÚÖ½ÉÏ»­³öÁËÁ½¸öÉ¥ÐIJ¡¿ñµÄÓÎÏ·

×òÌìÊÕÊ°¹ñ×Ó·¢ÏÖÁËСѧһЩ¶«Î÷£¬¿´µÄÄ¿µÉ¿Ú´ô£¬»ØÒäÆðÀ´Ö»¾õµÃ×Ô¼ºËûÂèµÄ¾ÍÊÇÒ»Ìì²Å¡£×ܹ²¿ª·¢ÁËÁ½¿îÓÎÏ·

ʲô½Ð¶ÔÊý¾ÝÃô¸Ð£¿ÔõÑù×öÊý¾Ý·ÖÎö£¿

½ñÌì½²Ò»ÏÂÎÒ¶ÔÊý¾ÝµÄÀí½â¡£Ò»¡¢´ÓÊý¾Ýά¶È×ö²ð·Ö£¬ÈÃÄ¿±ê¸ü¼ÓÂäµØÎÒ×ö¹ý½üÁ½ÄêµÄµçÉÌÔËÓª£¬ÆäÖид¥ºÜÉîµÄ

Õ¾³¤ÍƼö£º