关于Wireshark中解码DCE RPC存根数据及对比OPC DA客户端连接会话的技术咨询
Hey there! Let's work through your problem together. You're looking to compare connection sessions between two OPC DA clients connecting to a remote server, and since these clients rely on DCOM and DCE RPC under the hood, Wireshark's dcerpc dissector is the perfect starting point—though it's frustrating that it isn't decoding the stub data right now. Here's how to fix that and get your session comparison done:
First, ensure you're running a recent Wireshark version
Older Wireshark builds might lack full support for decoding OPC DA-specific DCE RPC stub data. Head toHelp > About Wiresharkto check your version; if it's pre-3.0, updating to the latest stable release will likely add better out-of-the-box support for OPC DA's COM interfaces.Enable explicit stub data decoding in DCERPC settings
Open Wireshark's preferences viaEdit > Preferences > Protocols > DCERPC. Look for options like "Enable dissection of stub data" or "Decode stub data for known interfaces" and make sure they're checked. If you're already capturing traffic, you can also right-click any DCERPC packet related to your OPC DA traffic, selectDecode As > DCERPC > OPC DAto force the dissector to use the correct interface definitions for that traffic stream.Use custom IDL files if built-in support isn't enough
OPC DA relies on standard COM interfaces (likeIOPCServerandIOPCItemMgt) defined in IDL files. If Wireshark doesn't have these interfaces pre-configured, you can create a custom dissector using Wireshark'sidl2wrstool (included with Wireshark's development kit):- Obtain the official OPC DA IDL files (these are available through OPC Foundation resources).
- Run the command
idl2wrs -o opcda_dissector.c opcda.idlto generate dissector code from the IDL file. - Compile this code into a Wireshark plugin (follow Wireshark's platform-specific plugin build guides) and load it into Wireshark. This will let the dcerpc dissector fully decode the stub data for OPC DA's specific interfaces.
Compare the two client sessions effectively
Once you have stub data decoding working, you can compare the sessions like this:- Capture traffic from each client in separate Wireshark capture files.
- Merge the two files using
File > Mergeto view both sessions in one window. - Apply a filter like
dcerpc.opcda && (ip.src == [client1-ip] || ip.src == [client2-ip])to isolate only the relevant OPC DA traffic from both clients. - Use
Statistics > Conversation List > DCERPCto compare metrics like session duration, number of RPC calls, and request/response latency between the two clients. You can also useFollow > TCP Streamon individual client packets to trace their full session flow side by side for direct comparison.
备注:内容来源于stack exchange,提问作者devaskim

