tcpdump によるパケット解析

tcpdump を使用したネットワークトラフィック解析を習得しましょう。ライブパケットのキャプチャ、Berkeley Packet Filter (BPF) の適用、生のペイロードの検査、そしてフォレンジック調査のための PCAP ファイルの管理方法を学びます。

Cybersecurity EngineerサイバーセキュリティWireshark

💡 このチュートリアルは英語版からAIによって翻訳されています。原文を確認するには、 ここをクリックしてください

はじめに

tcpdump によるパケット解析では、Linux command line から network evidence を収集、絞り込み、検査、保存する方法を学びます。4 個の guided lab で interface/live capture から BPF filter、payload、PCAP 管理へ進み、最後の challenge では step-by-step command なしで noisy incident capture を調査します。

isolated Ubuntu 22.04 training VM 内で生成した traffic と準備済み capture を使用します。packet に対する正確な問い、役立つ evidence の保持、unencrypted protocol が露出する情報の理解を重視します。

学習内容

  • capture interface を列挙し、tcpdump の compact packet summary を解釈
  • interface、packet count、snapshot length で live capture を制限
  • host、source/destination、port、protocol、logical combination の BPF expression を作成
  • full payload を ASCII と hex-plus-ASCII で表示
  • tcpdump と text filter で HTTP header や cleartext indicator を抽出
  • PCAP の書き込み、再生、filter と、focused evidence の抽出
  • prepared incident capture から suspicious host、FTP traffic、露出 credential を特定

このコースの対象者

command-line packet analysis の実践基礎を求める Security Analyst 志望者、SOC 学習者、network troubleshooting 担当者、Linux user 向けです。protocol analysis、IDS、network forensics の前段にも適します。

前提知識: 基本的な Linux shell と、IP address、TCP/UDP、port、client-server traffic の知識。tcpdump 経験は不要です。

学習環境: ブラウザー Ubuntu 22.04 VM で行う 5 個の独立 activity(4 guided lab、1 challenge)。local loopback/Web traffic、通常の VM interface traffic、準備済み PCAP を使い、tcpdump は導入済みです。

よくある質問

実在する external target の traffic を capture しますか?

いいえ。training VM の interface、local loopback/Web traffic、準備済み PCAP だけを使います。第三者 network の scan や interception は行いません。

一部の tcpdump command で sudo が必要なのはなぜですか?

live packet capture には interface への privileged access が必要です。自分が所有する PCAP の読み取りには通常不要で、lab で違いを説明します。

tcpdump はすべての connection の password を表示できますか?

いいえ。意図的に unencrypted な HTTP/FTP evidence で readable payload を示します。適切に暗号化された HTTPS/SSH は、通常の capture で application content を cleartext として露出しません。

どの network でもこの技術を使えますか?

所有しているか明示的な監視許可がある system/network だけで capture してください。PCAP には private communication や credential が含まれ得るため、scope、storage、sharing は policy と law に従う必要があります。

講師

labby
Labby
Labby is the LabEx teacher.