ÔõÑùÔÚLinuxÉÏÉèÖÃÍøÂç¼à¿ØºÍÁ÷Á¿ÆÊÎö
ÔõÑùÔÚlinuxÉÏÉèÖÃÍøÂç¼à¿ØºÍÁ÷Á¿ÆÊÎö
СÐò£º
Ëæ×Å»¥ÁªÍøµÄ¿ìËÙÉú³¤£¬ÍøÂçÇå¾²ºÍÁ÷Á¿ÆÊÎöÈÕÒæ³ÉΪÐÅÏ¢ÊÖÒÕÁìÓòÖÐÖ÷ÒªµÄ»°Ìâ¡£Õë¶ÔLinux²Ù×÷ϵͳ£¬±¾ÎĽ«ÏÈÈÝÔõÑùÔÚlinuxÉÏÉèÖÃÍøÂç¼à¿ØºÍÁ÷Á¿ÆÊÎö£¬×ÊÖú¶ÁÕ߸üºÃµØÏàʶºÍÖÎÀíÍøÂçÁ÷Á¿¡£
Ò»¡¢×°ÖúÍÉèÖÃÍøÂç¼à¿Ø¹¤¾ß
ÍøÂç¼à¿Ø¹¤¾ßÊÇÓÃÓÚʵʱ¼à²âºÍÆÊÎöÍøÂçÁ÷Á¿µÄÖ÷ÒªÈí¼þ¡£ÏÂÃæÊÇÔõÑù×°ÖúÍÉèÖÃÁ½¸öÖøÃûµÄÍøÂç¼à¿Ø¹¤¾ß£ºiftopºÍnload¡£
×°ÖÃiftop£º
sudo apt-get update sudo apt-get install iftop
µÇ¼ºó¸´ÖÆ
ÉèÖÃiftop£º
·¿ªÖնˣ¬ÊäÈëÒÔÏÂÏÂÁ
iftop -i eth0
µÇ¼ºó¸´ÖÆ
Õâ¸öÏÂÁÆô¶¯iftop£¬²¢¼à²âÍøÂç½Ó¿Úeth0ÉϵÄÁ÷Á¿¡£Äã¿ÉÒÔƾ֤ÐèÒªÌæ»»eth0ΪÄãµÄÍøÂç½Ó¿ÚÃû³Æ¡£
×°ÖÃnload£º
sudo apt-get update sudo apt-get install nload
µÇ¼ºó¸´ÖÆ
ÉèÖÃnload£º
ʹÓÃÒÔÏÂÏÂÁî×îÏÈʹÓÃnload£º
nload
µÇ¼ºó¸´ÖÆ
Õ⽫Æô¶¯nload£¬²¢ÏÔʾÍøÂç½Ó¿ÚµÄʵʱÁ÷Á¿ÐÅÏ¢¡£
¶þ¡¢Ê¹ÓÃWireshark¾ÙÐÐÍøÂçÁ÷Á¿²¶»ñºÍÆÊÎö
×°ÖÃWireshark£º
sudo apt-get update sudo apt-get install wireshark
µÇ¼ºó¸´ÖÆ
ÉèÖÃWireshark£º
ÊäÈëÒÔÏÂÏÂÁîÒÔÆô¶¯Wireshark£º
sudo wireshark
µÇ¼ºó¸´ÖÆ
Õ⽫·¿ªWiresharkµÄͼÐλ¯½çÃæ¡£ÔÚWireshark´°¿ÚÖУ¬Ñ¡ÕªÒª¼à²âµÄÍøÂç½Ó¿Ú£¬È»ºóµã»÷¡°×îÏÈ¡±°´Å¥×îÏȲ¶»ñÍøÂçÁ÷Á¿¡£
Èý¡¢Ê¹ÓÃtcpdump¾ÙÐÐÍøÂçÁ÷Á¿²¶»ñºÍÆÊÎö
×°ÖÃtcpdump£º
sudo apt-get update sudo apt-get install tcpdump
µÇ¼ºó¸´ÖÆ
ʹÓÃtcpdump£º
sudo tcpdump -i eth0 -w capture.pcap
µÇ¼ºó¸´ÖÆ
Õâ¸öÏÂÁ²¶»ñÍøÂç½Ó¿Úeth0ÉϵÄÁ÷Á¿£¬²¢½«ÆäÉúÑĵ½ÃûΪ”capture.pcap”µÄÎļþÖС£Äã¿ÉÒÔƾ֤ÐèÒªÌæ»»eth0ΪÄãµÄÍøÂç½Ó¿ÚÃû³Æ¡£
ËÄ¡¢Ê¹ÓÃtshark¾ÙÐÐÏÂÁîÐÐÍøÂçÁ÷Á¿ÆÊÎö
×°ÖÃtshark£º
sudo apt-get update sudo apt-get install tshark
µÇ¼ºó¸´ÖÆ
ʹÓÃtshark£º
tshark -r capture.pcap -T fields -e ip.src -e ip.dst -e frame.len
µÇ¼ºó¸´ÖÆ
Õâ¸öÏÂÁ¶Áȡ֮ǰ²¶»ñµÄÍøÂçÁ÷Á¿Îļþ”capture.pcap”£¬²¢ÏÔʾԴIPµØµã¡¢Ä¿µÄIPµØµãºÍÊý¾Ý°ü¾ÞϸµÈÐÅÏ¢¡£
Î塢ʹÓÃntop¾ÙÐÐÍøÂçÁ÷Á¿¼à¿ØºÍÆÊÎö
×°ÖÃntop£º
sudo apt-get update sudo apt-get install ntop
µÇ¼ºó¸´ÖÆ
ÉèÖÃntop£º
sudo /etc/init.d/ntop start
µÇ¼ºó¸´ÖÆ
Õâ¸öÏÂÁÆô¶¯ntop£¬²¢ÔÚÖÕ¶ËÉÏÏÔʾÁ÷Á¿Í³¼ÆÐÅÏ¢¡£Äã¿ÉÒÔͨ¹ý»á¼û http://localhost:3000 ÍøÖ·À´Éó²éntopµÄͼÐλ¯½çÃæ¡£
½áÂÛ£º
ͨ¹ý±¾ÎÄÌṩµÄÒªÁ죬Äã¿ÉÒÔÔÚLinuxϵͳÉÏÉèÖúÍʹÓÃÖÖÖÖÍøÂç¼à¿ØºÍÁ÷Á¿ÆÊÎö¹¤¾ß¡£ÕâЩ¹¤¾ß½«×ÊÖúÄã¸üºÃµØÏàʶºÍÖÎÀíÄãµÄÍøÂçÁ÷Á¿£¬Ìá¸ßÍøÂçÇå¾²ÐÔºÍÐÔÄÜ¡£Ï£Íû±¾ÎĶÔÄãÓÐËù×ÊÖú¡£
²Î¿¼×ÊÁÏ£º
Iftop: https://linux.die.net/man/8/iftop
Nload: https://linux.die.net/man/1/nload
Wireshark: https://www.wireshark.org/
Tcpdump: http://www.tcpdump.org/
Tshark: https://www.wireshark.org/docs/man-pages/tshark.html
Ntop: https://www.ntop.org/
ÒÔÉϾÍÊÇÔõÑùÔÚLinuxÉÏÉèÖÃÍøÂç¼à¿ØºÍÁ÷Á¿ÆÊÎöµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡