节点文献
基于WinPcap的网络协议分析系统的设计与实现
Design and Implementation of WinPcap Based Network Protocol Analysis System
【摘要】 概述了WinPcap的组成结构,介绍了以太网数据包捕获原理。基于WinPcap利用多线程技术实现对网络底层数据包的捕获。系统考虑到数据包捕获性能的问题,极大的降低了丢包率,对系统整体进行优化。对数据链路层捕获的数据包进行细致分析(即对以太网帧净载荷的十六进制数据分析)。将捕获的数据包按照各层网络协议格式对数据内容进行分析,为防止黑客攻击、网络安全以及入侵检测技术等提供理论依据。
【Abstract】 This paper summarizes the composition structure of WinPcap,and introduces the principle of Ethernet packet capture.Based on WinPcap,multi-threading technology is used to achieve the low-level network packet capture.Considering the data packet capture function problems,the system greatly reduces the packet loss rate,and optimizes itself entirely.A detailed analysis of the data packets captured by the data link layer is conducted(i.e.hexadecimal data analysis of the net load on the Ethernet frame).To provide a theoretical foundation for preventing hacker attacks,the network security and intrusion detection technology,the data content of captured data packets is analyzed according to the format of network protocol layers.
【Key words】 Winpcap; packet capture; multithreading; protocol analysis; net load;
- 【文献出处】 沈阳师范大学学报(自然科学版) ,Journal of Shenyang Normal University(Natural Science Edition) , 编辑部邮箱 ,2010年04期
- 【分类号】TP393.08
- 【被引频次】7
- 【下载频次】449