如何配置过滤器以区分并筛选TLS 1.3 Client Hello流量?
Great question—let's tweak your existing display filter to split out TLS 1.2 and 1.3 Client Hello traffic. Your current filter already nails targeting the right packets after the SSH handshake; we just need to add checks for the TLS version field that differentiates the two protocols.
How it works
TLS Client Hello packets include a handshake version field that's unique to each TLS version:
- TLS 1.2 uses
0x0303for this field - TLS 1.3 uses
0x0304
We can target this field by calculating its offset relative to your existing filter's TCP payload start point.
Final Filters
For TLS 1.2 Client Hello
tcp[tcp[12]/16*4]=22 and tcp[tcp[12]/16*4+5]=1 and tcp[tcp[12]/16*4+10:2] = 0x0303
For TLS 1.3 Client Hello
tcp[tcp[12]/16*4]=22 and tcp[tcp[12]/16*4+5]=1 and tcp[tcp[12]/16*4+10:2] = 0x0304
Breakdown of the new part
The added tcp[tcp[12]/16*4+10:2] checks the 2-byte handshake version field:
tcp[12]/16*4gets us the start of the TCP payload (your original base offset)- Adding
10moves us past the handshake identifier, TLS record header, and into the handshake protocol's version field :2specifies we're reading 2 consecutive bytes, which we compare to the version-specific hex values
This method is reliable because even though TLS 1.3 Client Hello packets might use the same TLS record layer version as 1.2 (0x0303), the handshake protocol version will always be 0x0304 for 1.3.
内容的提问来源于stack exchange,提问作者Praveen Patel

