| The network monitor technology is an important technology in the field of network security. It is utilized not only to diagnose network problem but also to record communication information and control the network communication. At present, the on-time multimedia services are increasing in the network, especially the ones based on SIP are applied widely. SIP has been an important protocol of control gradually. Meanwhile it's very important to construct information security system synchronized with the technology of communication network. Especially in the background that the criminals based on network are increasing gradually. Therefore, the thesis research the network monitor system aimed at SIP communication. It has not only theory meaning but also wide prospect of application.Firstly, this thesis introduces basic theory of the network monitor. Secondly it research the foundation of data package capture based on WinPcap and the protocols involved in the multi-media communication system based on SIP. Then it presents the design of SIP communication network monitor system as well as the implementation of key modules. At last it makes the test.Followings are two main aspects of this thesis.1. Researches on network monitor technologies and theories of data package capture. Then the theories of data package capture based on WinPcap including core level and user level are researched. The thesis analysis the NPF component in core level and its mechanism of capture and filtration as well as the wpcap.dll and packet.dll provided for user level which are the foundation of the system designed in the thesis.2. Design and implementation of SIP communication network monitor. The thesis designs a SIP communication network monitor system which is applied in the Ethernet, including the modules of data packet capture, SIP stack parser, voice data packet handling and monitor controlling. At last, the whole system receives sufficient test. |