Saturday, January 2, 2010

Exercise 3

a) Compare the destination port in the TCP packet in frame 3 with the destination port in the TCP packet in frame 12. What difference do you see? What does this tell you about the difference in the two requests?

The destination port in the TCP packet in frame 3 is HTTP (80) and in frame 12 is HTTPS (443). The request in frame 3 is a normal request but the request in frame 12 is a secure request.


The following table compares the two requests for web pages. For example, row i) shows that frames 1-2 and frames 8-9 represent the DNS lookups for each of the web requests.
Row www.yahoo.com
frames my.usf.com
frames Brief Explanation of Activity
i) 1-2 8-9 DNS Request to find IP address for common name & DNS Response
ii) 3-5 10-12 Three-way handshake
iii) -- 13-20
iv) 6 21 “Get” request for web page
v) 7 22 First packet from web server with web page content.


b) Explain what is happening in row “iii” above. Why are there no frames listed for yahoo in row “iii"?

Row “iii” in above table shows secure operations.
There are no frames listed for yahoo because it is not using SSL or secure page.

c) Look at the “Info” column on frame 6. It says: “GET / HTTP / 1.1. What is the corresponding Info field for the my.usf.com web request (frame 21)? Why doesn’t it read the same as in frame 6?

The corresponding Info field for the my.usf.com web request is “Application Data”.
It doesn’t read the same as in frame 6 because it is encrypted due to security reasons.

Exercise 2

a) In the first few packets, the client machine is looking up the common name (cname) of a web site to find its IP address. What is the cname of this web site? Give two IP addresses for this web site.
CNAME: www.yahoo.com
IP addresses:
• 216.109.117.106
• 216.109.117.109

b) How many packets/frames does it take to receive the web page (the answer to the first http get request only)?
It takes 22 packets to receive the web page.

c) Does this web site use gzip to compress its data for sending? Does it write cookies? In order to answer these questions, look under the payload for the reassembled packet that represents the web page. This will be the last packet from question b above. Look to see if it has “Content-Encoding” set to gzip, and to see if it has a “Set-Cookie” to write a cookie.
This web site does not use qzip to compress its data for sending.
This web site does not write cookies.

d) What is happening in packets 26 and 27? Does every component of a web page have to come from the same server? See the Hint to the left.
In packet 26, the server is sending query to another server.
In packet 27, the next server is responding to the main server.
This concludes that every component of a webpage do not have to come from same server. It might need smaller components from other server as well.

e) In packet 37 we see another DNS query, this time for us.i1.yimg.com. Why does the client need to ask for this IP address? Didn’t we just get this address in packet 26? (This is a trick question; carefully compare the two common names in packet 26 and 37.)

The DNS query made in packet 26 and 37 is different.

f) In packet 42 we see a HTTP “Get” statement, and in packet 48 a new HTTP “Get” statement. Why didn’t the system need another DNS request before the second get statement? Click on packet 42 and look in the middle window. Expand the line titled “Hypertext Transfer Protocol” and read the “Host:” line. Compare that line to the “Host:” line for packet 48.

In both packets, 42 and 48, the host is same: us.i1.yimg.com\r\n
So it does not require for another DNS query in the same session.

g) Examine packet 139. It is one segment of a PDU that is reassembled with several other segments in packet 160. Look at packets 141, 142, and 143. Are these three packets also part of packet 160? What happens if a set of packets that are supposed to be reassembled do not arrive in a continuous stream or do not arrive in the proper order?

Packets 141 and 142 are not the part of packet 160.
Packet 143 is a part of packet 160.
If a set of packets that are supposed to be reassembled do not arrive in a continuous stream or do not arrive in the proper order, it does not effect the main packet.


h) Return to examine frames 141 and 142. Both of these are graphics (GIF files) from the same source IP address. How does the client know which graphic to match up to each get statement? Hint: Click on each and look in the middle window for the heading line that starts with “Transmission Control Protocol”. What difference do you see in the heading lines for the two files? Return to the original “Get” statements. Can you see the same difference in the “Get” statements?

Both files in frames 141 and 142 are similar and from the same source IP address. The client knows the graphic to match up to each get statement from their “Stream Index”. Each of them have different “Stream Index”.

Exercise 1

a) What is the IP address of the client that initiates the conversation?
131.247.95.216

b) Use the first two packets to identify the server that is going to be contacted. List the common name, and three IP addresses that can be used for the server.
Server going to be contacted: www.google.com
The IP addresses that can be used for the server are:
• 64.233.161.99
• 64.233.161.104
• 64.233.161.147


c) What is happening in frames 3, 4, and 5?
In frame 3, connection establish request to the server 64.233.161.99
In frame 4, connection establish acknowledge to client 131.247.95.216. Acknowledge number=1
In frame 5, acknowledge returned to the server. Sequence number=1

d) What is happening in frames 6 and 7?
In frame 6, client is requesting server for URI (Uniform Resource Identifier)
In frame 7, server sends acknowledge for the request in frame 6

e) Ignore frame eight. However, for your information, frame eight is used to manage flow control.

f) What is happening in frames nine and ten? How are these two frames related?
In frame 9, acknowledge is set and forwarded to client
In frame 10, server is sending requested URI to client

g) What happens in packet 11?
Packet 11 is the acknowledge to the packets received in frame 10

h) After the initial set of packets is received, the client sends out a new request in packet 12. This occurs automatically without any action by the user. Why does this occur? See the first “hint” to the left.
The requested URI contains an image file which was not sent by the server in frame 10, which was in text format. So the client automatically asks for the image in another packet.

i) What is occurring in packets 13 through 22?
Packet 13 is acknowledge to packet 12. Packets 14 to 21 are requests and acknowledge related to the requested image file.
Packet 22 contains the image file that is finally sent to the client.

j) Explain what happens in packets 23 through 26. See the second “hint” to the left.
Frame 23 is an automatic request sent by the client
Frame 24 is the acknowledge to frame 23.
Frame 25 contains the image file requested by client.
Frame 26 is the acknowledge for received packet in frame 25.

k) In one sentence describe what the user was doing (Reading email? Accessing a web page? FTP? Other?).
The user was accessing the web page www.google.com.