Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Network

 Network

* OSI Layers
* Packet Format
* Wireshark Overview

Lawliet Shih

March 27, 2015
Tweet

Other Decks in Technology

Transcript

  1. OSI Layers • Application • Presentation • Session • Transport

    • Network • Data Link • Physical IP Packets are encapsulated in Ethernet Frames.
  2. Application Socket Transport TCP/UDP Segment Port Network IP Packet IP

    Network Interface (eth0 / wlan0) Data Link Ethernet Frame MAC Physical Application Socket Transport Network Network Interface Data Link Physical Data Data TCP Header Data TCP Header IP Header Data TCP Header IP Header Ethernet Header Ethernet Tail OSI Layers
  3. Application Transport Network Data Link UDP TCP IP ARP RARP

    ICMP RTSP SMTP DHCP SSH FTP RTP TFTP RTMP POP PPP Ethernet
  4. TCP

  5. UDP

  6. Port : 0 ~ 65535 1.well-known ports : 0 ~

    1023 2.registered ports : 1024 ~ 49151 3.dynamic / private ports : 49152 ~ 65535
  7. Destination IP Source IP Subnet Mask Destination Domain Source Domain

    compare Different : to Router Same : 1.ARP table 2.to ARP
  8. Data Link • HUB copy to every ports • Switch

    table : MAC Address <-> ports Broadcast or Multicast
  9. Data Link Ethernet Card receives Frames : • if ((Destination

    MAC Address) == (MACAddress) ) • Broadcast or Multicast • Promiscuous Mode
  10. Application Socket Transport TCP/UDP Segment Port Network IP Packet IP

    Network Interface (eth0 / wlan0) Data Link Ethernet Frame MAC Physical Application Socket Transport Network Network Interface Data Link Physical Data Data TCP Header Data TCP Header IP Header Data TCP Header IP Header Ethernet Header Ethernet Tail 14 20 20 ? 4 MTU = MSS + TCP/UDP Header + IP Header Ethernet Default :1500 1460 + 20 (TCP) + 20 1472 + 8 (UDP) + 20 • MTU : Maximum Transmission Unit • MSS : Maximum Segment Size • Ethernet Frame Range : 64 ~ 1518 • Data : Payload
  11. 9

  12. Expert Information • Out-of-Order Segment (packet arrives < 3 ms)

    • Packet loss Recovery - Duplicate ACK Fast Retransmission (packet arrives < 20 ms of a Duplicate ACK) - Retransmission (packet arrive > 3 ms and not related to Duplicte ACK) (packet arrives >= 20 ms of Duplicate ACK)