Wireshark/tcpdump를 활용한 패킷 캡처
명령줄에서 `tcpdump`를 사용하고 Wireshark로 그래픽 분석을 수행하여 네트워크 패킷을 캡처하고 분석하는 방법을 학습합니다.
Wireshark/tcpdump를 활용한 패킷 캡처은(는) CoddyKit의 무료 Linux Networking & TCP/IP for Developers 강의입니다. 이것은 4개 중 1번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Linux Networking & TCP/IP for Developers 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Linux Networking & TCP/IP for Developers 강의에는 총 4개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
What is Packet Capture?
Packet capture is like taking a snapshot of all the network data flowing in and out of your device. It's a powerful technique for understanding network behavior and troubleshooting issues.
You can see the raw "packets" of information, including their source, destination, and the data they carry. This helps diagnose slow connections, find security problems, or debug network applications.
Introducing `tcpdump`
tcpdump is a command-line utility for capturing and analyzing network traffic. It's pre-installed on most Linux systems, making it a go-to tool for quick network inspections.
It works by "sniffing" packets directly from your network interface. You can view them in real-time or save them for later analysis.
Basic Capture with `tcpdump`
Let's start with the most basic usage: capturing all traffic on a specific network interface. You often need sudo privileges to run tcpdump.
The -i flag specifies the interface (e.g., eth0 or wlan0). If you omit -i, tcpdump tries to pick one automatically.
sudo tcpdump -i eth0Filtering by Host
Capturing all traffic can be overwhelming. You'll often want to filter for specific connections. The host keyword lets you capture traffic to or from a particular IP address or hostname.
sudo tcpdump -i eth0 host 192.168.1.1Filtering by Port
Another common filter is by port. This is useful for seeing traffic related to specific services, like web (port 80/443), SSH (port 22), or DNS (port 53).
sudo tcpdump -i eth0 port 80Combining Filters
You can combine filters using logical operators like and, or, and not. This allows for very precise targeting of the traffic you want to see.
For example, to see HTTP traffic to a specific host, you'd combine host and port.
sudo tcpdump -i eth0 host 192.168.1.1 and port 80Saving to a File (`.pcap`)
For deeper analysis, it's best to save the captured packets to a file. The -w flag writes the raw packet data to a file with a .pcap extension. This file can then be opened by other tools.
The -c flag limits the number of packets to capture.
sudo tcpdump -i eth0 -c 100 -w my_capture.pcapWireshark: The GUI Analyzer
While tcpdump is excellent for command-line capture, Wireshark is the industry-standard graphical tool for deep packet inspection. It provides a user-friendly interface to visualize and analyze captured network data.
Wireshark can capture live traffic or open .pcap files created by tcpdump or other tools.
Importing `tcpdump` Files
A common workflow is to capture packets using tcpdump on a remote server (where a GUI might not be available) and then transfer the .pcap file to your local machine for analysis with Wireshark.
In Wireshark, you simply go to File > Open and select your .pcap file. Wireshark will then display all the captured packets in a structured way.
`tcpdump` Filter Challenge
You need to capture traffic on the eth0 interface that is going to or coming from the IP address 10.0.0.5, but ONLY on port 22 (SSH). Which tcpdump command would achieve this?
Lesson Recap
In this lesson, we explored the powerful world of packet capture. We learned how to use tcpdump to capture and filter network traffic directly from the command line.
- Basic capture with
-i - Filtering by
hostandport - Combining filters with
and,or,not - Saving captures to a
.pcapfile with-w
We also introduced Wireshark as a graphical tool for in-depth analysis of these captured files. Mastering these tools is crucial for any network troubleshooter!
AI 튜터와 함께 Linux Networking & TCP/IP for Developers을(를) 배우세요 — 무료
브라우저에서 실제 코드를 작성하고 실행하며, 24/7 AI 튜터로부터 즉각적인 도움을 받고, 웹이나 앱에서 중단한 부분부터 계속 학습하세요.
- 코스
- 12
- 레슨
- 48
자주 묻는 질문
“Wireshark/tcpdump를 활용한 패킷 캡처” 강의는 무료인가요?
네 — “Wireshark/tcpdump를 활용한 패킷 캡처” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Linux Networking & TCP/IP for Developers 강의 전체를 잠금 해제할 수 있습니다. Linux Networking & TCP/IP for Developers 강의에는 총 4개의 강의가 포함되어 있습니다.
“Wireshark/tcpdump를 활용한 패킷 캡처”에서 뭘 배우나요?
명령줄에서 `tcpdump`를 사용하고 Wireshark로 그래픽 분석을 수행하여 네트워크 패킷을 캡처하고 분석하는 방법을 학습합니다. 브라우저에서 직접 실행하는 실습 코드로 Linux Networking & TCP/IP for Developers을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
Linux Networking & TCP/IP for Developers을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 Linux Networking & TCP/IP for Developers은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 1번째 강의입니다.
“Wireshark/tcpdump를 활용한 패킷 캡처” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 Linux Networking & TCP/IP for Developers 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 Linux Networking & TCP/IP for Developers 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.
이 강의의 모든 강의
- Wireshark/tcpdump를 활용한 패킷 캡처
- 네트워크 성능 도구
- Linux 방화벽(Netfilter/iptables)
- dig 및 nslookup을 사용한 DNS 진단