首页 | 本学科首页   官方微博 | 高级检索  
     

浅谈在Linux系统中以太网数据帧的监听与分析
作者单位:集美轻工业学校
摘    要:以太网数据传输通过广播实现,在同一网段的所有网卡事实上都可以访问在共享的物理介质上传输的所有数据。但在系统正常工作时,一个合法的网络接口应只响应两种数据帧:一是帧的目标MAC地址与本地MAC地址相符;二是帧的目标地址是广播地址。若要监听所有流经网卡的数据帧,当用于监听的主机连接在共享型以太网集线器上时,采用"混杂"模式可以监听到同一冲突域上传输的数据帧;但当监听的主机连接在交换机上时,可以利用交换机的端口镜像(Port Mirroring)功能实现监听。

关 键 词:数据帧  MAC地址  “混杂”模式  端口镜像

On Monitor and Analysis of the Ethernet Data Frame in Linux System
YANG Cheng-hui. On Monitor and Analysis of the Ethernet Data Frame in Linux System[J]. Digital Community & Smart Home, 2008, 0(30)
Authors:YANG Cheng-hui
Abstract:The transmission of the data on Ethernet is achieved through broadcasting.In fact all the network cards in the same network have access to all the data transmitted by the shared physical agent.However,when the system works normally,a legitimate network interface should respond to only two types of data frames.One is when the target MAC address of the frame is consistent with the local MAC ad-dress.The other is when the target address of the frame is the broadcast address.To monitor all the data frames flowing from the network card,promiscuous mode is adopted to monitor the data frame transmitted in the same collision domain,when the host for monitoring con-nected to the shared Ethernet hub.Whereas when the host for monitoring is connected to the switch,we can use the Port Mirroring of the switch for monitoring.
Keywords:Data frame  MAC address  Promiscuous mode  Port mirror  
本文献已被 CNKI 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号