This repository has been archived on 2026-05-19. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
obsidian/CS/NET/网络协议分析基础.md
T
2026-04-20 22:47:51 +08:00

209 lines
5.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
tags: [network, protocol, theory, cs]
create time: 2026-04-17 12:15
---
# 网络协议分析基础
## 概述
网络协议分析是理解网络通信的核心技术,通过分析数据包的结构和内容,可以深入理解网络协议的工作原理和通信机制。
## 正文
### TCP 三次握手与四次挥手
#### 三次握手 (SYN, SYN-ACK, ACK)
```
客户端 服务器
| |
| --- SYN, seq=x --------------------> |
| |
| <--- SYN, ACK, seq=y, ack=x+1 ------ |
| |
| --- ACK, seq=x+1, ack=y+1 ---------> |
| | 连接建立
```
**各字段含义:**
- **SYN**: 同步标志,用于建立连接
- **ACK**: 确认标志,表示确认收到
- **seq**: 序列号,确保数据有序传递
- **ack**: 确认号,表示期望收到的下一个序列号
**抓包特征:**
1. 第一个包:SYN 标志位为 1,ACK 为 0
2. 第二个包:SYN 和 ACK 都为 1
3. 第三个包:ACK 为 1,SYN 为 0
#### 四次挥手 (FIN, ACK, FIN, ACK)
```
客户端 服务器
| |
| --- FIN, seq=x --------------------> | 主动关闭
| |
| <--- ACK, seq=y, ack=x+1 ----------- |
| | 半关闭
| <--- FIN, seq=y ------------------- | 被动关闭
| |
| --- ACK, seq=x+1, ack=y+1 ---------> |
| | 连接关闭
```
**状态转换:**
- FIN_WAIT_1: 主动关闭方发送 FIN
- FIN_WAIT_2: 主动关闭方收到 ACK,等待对方 FIN
- CLOSE_WAIT: 被动关闭方收到 FIN,进入半关闭状态
- LAST_ACK: 被动关闭方发送 FIN
- TIME_WAIT: 主动关闭方收到 FIN,等待 2MSL 后完全关闭
### HTTP 协议分析
#### 请求结构
```
Method Request-URI HTTP-Version\r\n
Header-Name: Header-Value\r\n
\r\n
Message-Body
```
**常见方法:**
- **GET**: 获取资源
- **POST**: 提交数据
- **PUT**: 更新资源
- **DELETE**: 删除资源
- **HEAD**: 获取响应头
- **OPTIONS**: 获取支持的方法
**常用请求头:**
```
Host: example.com
User-Agent: Mozilla/5.0
Accept: text/html,application/json
Content-Type: application/json
Authorization: Bearer token
Cookie: session=xxx
```
#### 响应结构
```
HTTP-Version Status-Code Reason-Phrase\r\n
Header-Name: Header-Value\r\n
\r\n
Message-Body
```
**状态码分类:**
- **2xx**: 成功 (200 OK, 201 Created, 204 No Content)
- **3xx**: 重定向 (301 Moved Permanently, 302 Found, 304 Not Modified)
- **4xx**: 客户端错误 (400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found)
- **5xx**: 服务器错误 (500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable)
**常用响应头:**
```
Content-Type: application/json; charset=utf-8
Content-Length: 1234
Cache-Control: max-age=3600
ETag: "abc123"
Set-Cookie: session=xxx; Path=/; HttpOnly
```
### TLS/SSL 加密通信
#### TLS 握手流程
```mermaid
sequenceDiagram
participant C as 客户端
participant S as 服务器
C->>S: ClientHello<br/>(支持的加密套件、随机数)
S-->>C: ServerHello<br/>(选择的加密套件、随机数、证书)
S-->>C: Certificate<br/>(服务器证书)
S-->>C: ServerHelloDone
C->>S: ClientKeyExchange<br/>(预主密钥,用服务器公钥加密)
C->>S: ChangeCipherSpec<br/>(通知后续使用加密通信)
C->>S: Finished<br/>(握手完成,加密验证)
S-->>C: ChangeCipherSpec
S-->>C: Finished
Note over C,S: 开始加密通信
```
**关键概念:**
- **证书链**: 从服务器证书到根证书的信任链
- **预主密钥**: 通过非对称加密传输,用于生成会话密钥
- **会话密钥**: 通过预主密钥和双方随机数生成,用于对称加密
- **SSL Pinning**: 客户端验证服务器证书,防止中间人攻击
### 数据包分析要点
#### 抓包指标
**性能指标:**
- **RTT (Round Trip Time)**: 往返时延
- **吞吐量**: 单位时间传输的数据量
- **丢包率**: 丢失的数据包比例
- **重传率**: 重发数据包的比例
**连接指标:**
- **TCP 窗口大小**: 接收窗口和拥塞窗口
- **连接状态**: ESTABLISHED, TIME_WAIT 等
- **连接复用**: Keep-Alive, HTTP/2 连接复用
#### 过滤技巧
**基于协议过滤:**
```
# HTTP/HTTPS
http or http2 or ssl
# TCP 特定标志
tcp.flags.syn == 1 # SYN 包
tcp.flags.ack == 1 # ACK 包
tcp.flags.fin == 1 # FIN 包
tcp.flags.reset == 1 # RST 包
```
**基于内容过滤:**
```
# 特定 User-Agent
http.user_agent contains "Chrome"
# 特定域名
http.host == "example.com"
# HTTP 错误
http.response.code >= 400
# 请求体内容
http.file_data contains "keyword"
```
**基于网络层过滤:**
```
# 源/目标地址
ip.src == 192.168.1.1
ip.dst == 192.168.1.1
# 端口范围
tcp.port >= 1024 and tcp.port <= 65535
```
## 关联笔记
- [[CS/TOOLS/网络抓包]]
- [[CS/SECURITY/网络安全基础]]
- [[CS/OS/TCP 协议详解]]
## 参考资源
- RFC 文档: https://www.rfc-editor.org/
- Wireshark 指南: https://www.wireshark.org/docs/wsug_html_chunked/