728x90

 

Wireshark

 Wireshark๋Š” ๋„คํŠธ์›Œํฌ ํŒจํ‚ท ๋ถ„์„(Network Packet Analyzer) ๋„๊ตฌ๋กœ, ๋„คํŠธ์›Œํฌ์—์„œ ์ „์†ก๋˜๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์บก์ฒ˜ํ•˜๊ณ  ๋ถ„์„ํ•  ์ˆ˜ ์žˆ๋Š” ์˜คํ”ˆ ์†Œ์Šค ์†Œํ”„ํŠธ์›จ์–ด ์ž…๋‹ˆ๋‹ค. ์‹ค์‹œ๊ฐ„ ํŒจํ‚ท, ํ”„๋กœํ† ์ฝœ ๋ถ„์„ ๊ธฐ๋Šฅ์„ ํ†ตํ•ด ๋„คํŠธ์›Œํฌ ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ…, ๋ณด์•ˆ ์ทจ์•ฝํƒ์ง€, ์›น์‚ฌ์ดํŠธ ์„ฑ๋Šฅ ๋ถ„์„, ํŒจํ‚ท ์Šค๋‹ˆํ•‘ ๋ฐ ํฌ๋ Œ์‹์„ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

 

 wireshark๋Š” ๋„คํŠธ์›Œํฌ์— ๋Œ์•„๋‹ค๋‹ˆ๋Š” ์ˆ˜ ๋งŽ์€ ํŒจํ‚ท๋“ค์„ ๋ณด์—ฌ ์ฃผ๋Š”๋ฐ ๋„ˆ๋ฌด ๋งŽ๋‹ค๋ณด๋‹ˆ ์ƒ‰์ƒ์œผ๋กœ ์•Œ์•„๋ณด๊ธฐ ์ข‹๊ฒŒ ํ‘œ์‹œ๋ฅผ ํ•ด์ค๋‹ˆ๋‹ค. 

 

** View > Coloring Rules๋ฅผ ํ†ตํ•ด ํ‘œ์‹œ ์—ฌ๋ถ€๋ฅผ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

Color Rules Info

ํ•ญ๋ชฉ ์„ค๋ช… ํ•„ํ„ฐ ์กฐ๊ฑด
Bad TCP TCP ํŒจํ‚ท์—์„œ ์˜ค๋ฅ˜๊ฐ€ ๊ฐ์ง€๋œ ๊ฒฝ์šฐ (์˜ˆ: ์†์‹ค, ์žฌ์ „์†ก) tcp.analysis.flags && !
tcp.analysis.window_update && !
tcp.analysis.keep_alive && !
tcp.analysis.keep_alive_ack
HSRP State Change HSRP(Hot Standby Router Protocol)์˜ ์ƒํƒœ ๋ณ€๊ฒฝ ๊ฐ์ง€ hsrp.state != 8 && hsrp.state != 16
Spanning Tree Topology Change ์ŠคํŒจ๋‹ ํŠธ๋ฆฌ ํ”„๋กœํ† ์ฝœ(STP)์˜ ํ† ํด๋กœ์ง€ ๋ณ€๊ฒฝ ๊ฐ์ง€ stp.type == 0x80
OSPF State Change OSPF(Open Shortest Path First) ์ƒํƒœ ๋ณ€๊ฒฝ ๊ฐ์ง€ ospf.msg != 1
ICMP errors ICMP ๋˜๋Š” ICMPv6์—์„œ ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€ ๋ฐœ์ƒ (์˜ˆ: ๋ชฉ์ ์ง€ ๋„๋‹ฌ ๋ถˆ๊ฐ€) `icmp.type in { 3..5, 11 }
ARP ARP(Address Resolution Protocol) ํŒจํ‚ท ๊ฐ์ง€ arp
ICMP ICMP ๋˜๋Š” ICMPv6 ํŒจํ‚ท ๊ฐ์ง€ `icmp
TCP RST TCP ์—ฐ๊ฒฐ์ด ๊ฐ•์ œ๋กœ ์ข…๋ฃŒ๋จ (Reset) tcp.flags.reset eq 1
SCTP ABORT SCTP(Stream Control Transmission Protocol) ์—ฐ๊ฒฐ์ด ์ข…๋ฃŒ๋จ sctp.chunk_type eq ABORT
IPv4 TTL low or unexpected ์˜ˆ์ƒ๋˜์ง€ ์•Š์€ ๋‚ฎ์€ TTL(Time To Live) ๊ฐ’ ๊ฐ์ง€ `(ip.dst != 224.0.0.0/4 && ip.ttl < 5 && !(pim
IPv6 hop limit low or unexpected ์˜ˆ์ƒ๋˜์ง€ ์•Š์€ ๋‚ฎ์€ IPv6 hop limit ๊ฐ์ง€ `(ipv6.dst != ff00::/8 && ipv6.hlim < 5 && !(ospf
Checksum Errors ํŒจํ‚ท์˜ ์ฒดํฌ์„ฌ ์˜ค๋ฅ˜ ๊ฐ์ง€ `eth.fcs.status==โ€œBadโ€
SMB SMB(Server Message Block) ํŠธ๋ž˜ํ”ฝ ๊ฐ์ง€ `smb
HTTP HTTP ๋˜๋Š” HTTP/2 ํŠธ๋ž˜ํ”ฝ ๊ฐ์ง€ `http
DCERPC DCE/RPC(Distributed Computing Environment / Remote Procedure Call) ํŠธ๋ž˜ํ”ฝ ๊ฐ์ง€ dcerpc
Routing ๋ผ์šฐํŒ… ํ”„๋กœํ† ์ฝœ ๊ฐ์ง€ (์˜ˆ: HSRP, OSPF, BGP) `hsrp
TCP SYN/FIN TCP ์„ธ์…˜ ์„ค์ • ๋˜๋Š” ์ข…๋ฃŒ ๊ฐ์ง€ `tcp.flags & 0x02
TCP ๋ชจ๋“  TCP ํŠธ๋ž˜ํ”ฝ ๊ฐ์ง€ tcp
UDP ๋ชจ๋“  UDP ํŠธ๋ž˜ํ”ฝ ๊ฐ์ง€ udp
Broadcast ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ํŒจํ‚ท ๊ฐ์ง€ eth[0] & 1
System Event ์‹œ์Šคํ…œ ๋กœ๊ทธ ๋ฐ ๊ด€๋ จ ์ด๋ฒคํŠธ ๊ฐ์ง€ `systemd_journal

 

๋ฐ˜์‘ํ˜•
๋‹คํ–ˆ๋‹ค