用 Dumpcap 在 Debian 上进行网络安全审计
一 合规与准备
二 安装与权限配置
sudo apt update && sudo apt install -y wireshark dumpcapsudo groupadd -r dumpcapsudo chown root:dumpcap /usr/bin/dumpcap && sudo chmod 750 /usr/bin/dumpcapsudo setcap cap_net_raw,cap_net_admin=eip /usr/bin/dumpcapsudo usermod -aG dumpcap $USER(需重新登录生效)sudo groupadd -r wireshark(若未存在)sudo usermod -aG wireshark $USERsudo setcap cap_net_raw,cap_net_admin=eip /usr/bin/dumpcap三 捕获策略与常用命令
dumpcap -Dsudo dumpcap -i eth0 -w capture.pcapsudo dumpcap -i eth0 -f "tcp port 80" -w http_only.pcapsudo dumpcap -i eth0 -f "tcp port 80 and host 192.0.2.10" -w host80.pcapsudo dumpcap -i eth0 -G 60 -W bysec -w cap_%Y-%m-%d_%H-%M-%S.pcapsudo dumpcap -i eth0 -a filesize:1000 -w cap.pcapngsudo dumpcap -i eth0 -c 1000 -w first1000.pcapsudo dumpcap -i eth0 -l | tshark -r -四 审计分析与取证流程
wireshark cap_2026-01-04_10-00-00.pcapngip.addr == 192.0.2.10http.requestdns.qry.name contains "example"tshark -r cap.pcap -Y "http" -T fields -e frame.number -e ip.src -e ip.dst -e http.host -e http.request.method -e http.request.uritshark -r cap.pcap -q -z conv,tcp -z io,stat,60五 运行安全与加固建议