You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置过滤器以区分并筛选TLS 1.3 Client Hello流量?

Distinguishing TLS 1.2 vs 1.3 Client Hello Packets in Your Filter

Great question—let's tweak your existing display filter to split out TLS 1.2 and 1.3 Client Hello traffic. Your current filter already nails targeting the right packets after the SSH handshake; we just need to add checks for the TLS version field that differentiates the two protocols.

How it works

TLS Client Hello packets include a handshake version field that's unique to each TLS version:

  • TLS 1.2 uses 0x0303 for this field
  • TLS 1.3 uses 0x0304

We can target this field by calculating its offset relative to your existing filter's TCP payload start point.

Final Filters

For TLS 1.2 Client Hello

tcp[tcp[12]/16*4]=22 and tcp[tcp[12]/16*4+5]=1 and tcp[tcp[12]/16*4+10:2] = 0x0303

For TLS 1.3 Client Hello

tcp[tcp[12]/16*4]=22 and tcp[tcp[12]/16*4+5]=1 and tcp[tcp[12]/16*4+10:2] = 0x0304

Breakdown of the new part

The added tcp[tcp[12]/16*4+10:2] checks the 2-byte handshake version field:

  • tcp[12]/16*4 gets us the start of the TCP payload (your original base offset)
  • Adding 10 moves us past the handshake identifier, TLS record header, and into the handshake protocol's version field
  • :2 specifies we're reading 2 consecutive bytes, which we compare to the version-specific hex values

This method is reliable because even though TLS 1.3 Client Hello packets might use the same TLS record layer version as 1.2 (0x0303), the handshake protocol version will always be 0x0304 for 1.3.

内容的提问来源于stack exchange,提问作者Praveen Patel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 17:09:03