標籤:數字 程式 長度 sig 組管理 協議 資料 結構 alt
這幾天完成一個對比乙太網路幀的程式(c語言),老師給了乙太網路幀頭部和IP報文頭部的結構體,跟實際抓取到的資料包的格式是相同的。
乙太網路幀頭部的資料結構:
typedef struct { unsigned char dest_mac[6]; unsigned char src_mac[6]; unsigned short eth_type;} ethernet_header;
eth_type欄位用來指明上層協議類型,兩位元組。eth_type欄位常見值及對應協議
0x0800 網際協議(IP)
0x0806 位址解析通訊協定(ARP)
0x8035 反向位址解析通訊協定
更多可見:http://blog.sina.com.cn/s/blog_a206e924010111tm.html
IP報文格式頭部的資料結構:
typedef struct { unsigned char header_len:4; unsigned char version:4; unsigned char tos:8; unsigned short total_len; unsigned short ident; unsigned short flags; unsigned char ttl:8; unsigned char proto:8; unsigned short checksum; unsigned char src_ip[4]; unsigned char dest_ip[4];} ip_header;
IP報文的格式
IP報文中有的欄位只佔了4位,結構體中的成員採用了位域定義的形式。
struct name{
type name:n;
};
成員變數name佔用空間為n位,n必須為正整數,其值必須小於type類型佔用的位元,如果type是int,那麼n必須是1~31之間的整數。對於位域類型的成員,在賦值時如果實際值超過n位能表達的範圍,超出部分將會被截掉。
結構體中 首部長度欄位 在 版本欄位的前面,跟圖片中的相反,是因為網路位元組序表示的原因。
proto表示傳輸層的協議,常見的對應描述:
1 Internet控制訊息(ICMP)
2 Internet組管理(IGMP)
6 傳輸控制(TCP)
17 使用者資料報文(UDP)
更多見:http://blog.csdn.net/jiary5201314/article/details/41213561
IP報文中的前序長度欄位表示的是頭部佔32位元的數字,即IP報文頭部的長度為 header_len * 4 位元組。
乙太網路幀、IP報文格式