tcpflowã使ã£ã¦ãã±ããç£è¦
ä½ããã©ãã«ãèµ·ãã£ãã¨ããã¢ããªã±ã¼ã·ã§ã³ã®ãã°ãè¦ãããããã±ããç´æ¥è¦ãæ¹ãæ©ãã£ã¦ã°ãã¡ãããè¨ã£ã¦ãã
åèï¼http://www.slideshare.net/takafumionaka/ss-5852561
ã¨ããã¢ããªã®éçºéç¨(ãã©ãã«ã·ã¥ã¼ã)
Debianç°å¢ã§ä½¿ãã
ã¾ãã¯ã¤ã³ã¹ãã¼ã«
sudo aptitude install tcpflow
tcpflowã®ãã«ããè¦ãã
usage: tcpflow [-chpsv] [-b max_bytes] [-d debug_level] [-f max_fds] [-i iface] [-w file] [expression] -b: max number of bytes per flow to save -c: console print only (don't create files) -C: console print only, but without the display of source/dest header -d: debug level; default is 1 -e: output each flow in alternating colors -f: maximum number of file descriptors to use -h: print this help message -i: network interface on which to listen (type "ifconfig -a" for a list of interfaces) -p: don't use promiscuous mode -r: read packets from tcpdump output file -s: strip non-printable characters (change to '.') -v: verbose operation equivalent to -d 10 expression: tcpdump-like filtering expression
- c ãå¿ããã¨å¤§å¤ãªãã¨ã«ãªãã®ã§å¿ããªãã¨ããã¨æãã¾ãã
ç£è¦ãããããã¯ã¼ã¯ã¢ããã¿ãæ¢ãã
ifconfig -a
ã§ãç£è¦
sudo tcpflow -c port 80 -i lo
80çªãã¼ãã§ã¢ã¯ã»ã¹ããã¨ãã°ãæµããã®ã§ãç£è¦æåããã