Analysis of HTTP Protocol using Wireshark
Experiment
Study and Analysis of HTTP Protocol Using Wireshark
Aim
To capture and analyze HTTP packets using Wireshark and study the structure of HTTP request and response messages.
Objectives
After completing this experiment, students will be able to:
- Understand the working of the HTTP protocol.
- Capture network packets using Wireshark.
- Apply protocol filters in Wireshark.
- Analyze HTTP GET requests and HTTP response messages.
- Identify important HTTP header fields.
- Calculate the response time of a web request.
- Understand client-server communication using HTTP.
Theory
HTTP (Hypertext Transfer Protocol)
HTTP is an application layer protocol used for communication between a web browser (client) and a web server. It follows the request-response model.
When a user enters a website address in the browser:
- The browser sends an HTTP Request to the server.
- The server processes the request.
- The server returns an HTTP Response containing the requested webpage.
HTTP generally uses
- Port Number : 80
- Transport Protocol : TCP
Note: Most modern websites use HTTPS (HTTP Secure) on port 443. Since HTTPS encrypts the data, the HTTP contents are not visible in Wireshark. For this experiment, use a website that supports plain HTTP (for example, http://neverssl.com).
HTTP Communication
HTTP Request
Browser ---------------------> Web Server
HTTP Response
Browser <--------------------- Web Server
HTTP Request Format
GET /index.html HTTP/1.1
Host: example.com
User-Agent: Mozilla/5.0
Accept: text/html
Accept-Language: en-US
Accept-Encoding: gzip, deflate
Connection: keep-alive
HTTP Response Format
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 5120
Last-Modified: Tue, 10 Jun 2025 08:30:00 GMT
<HTML DATA>
Software Required
- Wireshark
- Google Chrome / Mozilla Firefox / Microsoft Edge
- Internet Connection
Procedure
Step 1
Open Wireshark.
Step 2
Select the active network interface (Wi-Fi or Ethernet).
Click
Start Capturing Packets
Step 3
Clear the browser cache.
For Chrome
Settings
→ Privacy and Security
→ Clear Browsing Data
Clear Cached Images and Files.
Step 4
Open the browser.
Visit an HTTP website such as
http://neverssl.com
or
http://httpforever.com
Wait until the webpage loads completely.
Step 5
Return to Wireshark.
Stop packet capture.
Capture
→ Stop
Step 6
In the filter box enter
http
Click Apply.
Only HTTP packets will now be displayed.
Understanding the Packet List
You will observe packets similar to
No. Protocol Info
25 HTTP GET / HTTP/1.1
26 HTTP HTTP/1.1 200 OK
The first packet is the HTTP Request.
The second packet is the HTTP Response.
Packet Analysis
Click the first GET packet.
Expand
Hypertext Transfer Protocol
You will see
GET / HTTP/1.1
Host:
User-Agent:
Accept:
Accept-Language:
Accept-Encoding:
Answer the Following Questions
(a) Find the Source IP Address and Destination IP Address of the First GET Message
Expand
Internet Protocol Version 4
Example
Source Address
192.168.1.15
Destination Address
34.117.59.81
Answer
Source IP Address
192.168.1.15
Destination IP Address
34.117.59.81
Explanation
- Source IP is the client's computer.
- Destination IP is the web server.
(b) Determine the Medium Format, Language, Encoding and Character Set Accepted by the Client
Expand the HTTP request.
Observe the following fields.
Accept
Accept:
text/html,
application/xhtml+xml,
application/xml
This specifies the media formats accepted by the browser.
Answer
Medium Format
text/html
application/xhtml+xml
application/xml
Accept-Language
Example
Accept-Language:
en-US,en;q=0.9
Answer
Language
English (United States)
English
Accept-Encoding
Example
gzip, deflate, br
Answer
Encoding
gzip
deflate
brotli (br)
Accept-Charset
Older browsers may display
Accept-Charset
UTF-8
Modern browsers usually omit this field because UTF-8 is assumed by default.
Answer
Character Set
UTF-8 (if present)
Otherwise
Not explicitly specified
(c) Determine the URL and User Agent
Host Field
Example
Host
neverssl.com
Request URI
/
Hence
Complete URL
http://neverssl.com/
User-Agent
Example
Mozilla/5.0
Windows NT 10.0
AppleWebKit
Chrome
Answer
Browser
Google Chrome
Operating System
Windows 10
Rendering Engine
AppleWebKit
(d) Determine the Source and Destination IP Address of the First Response Message
Click
HTTP/1.1 200 OK
Expand
Internet Protocol
Example
Source
34.117.59.81
Destination
192.168.1.15
Notice that the addresses are reversed.
Answer
Source
Server
Destination
Client
(e) Determine the Status Code
Expand
Hypertext Transfer Protocol
Example
HTTP/1.1 200 OK
Status Code
200
Meaning
Request Successful
Common HTTP Status Codes
| Code | Meaning |
|---|---|
| 200 | OK |
| 301 | Moved Permanently |
| 302 | Redirect |
| 304 | Not Modified |
| 400 | Bad Request |
| 401 | Unauthorized |
| 403 | Forbidden |
| 404 | Not Found |
| 500 | Internal Server Error |
(f) Determine When the HTML File Was Last Modified
Locate
Last-Modified
Example
Last-Modified
Tue, 10 Jun 2025 08:30:00 GMT
This indicates the last modification time of the webpage on the server.
(g) Determine the Content-Length
Locate
Content-Length
Example
Content-Length
5120
Meaning
The HTML page size is
5120 bytes
(h) Calculate the Time Taken to Receive the Response
Observe
GET Packet
Time
3.420001 seconds
Response Packet
Time
3.468945 seconds
Therefore
Response Time
3.468945
−
3.420001
=
0.048944 seconds
Approximately
49 milliseconds
Formula
Response Time
=
Response Timestamp
−
GET Timestamp
(i) Determine the HTTP Version
Observe the first line of the GET request.
Example
GET / HTTP/1.1
Hence
HTTP Version
HTTP/1.1
Some browsers communicating over newer protocols may instead use HTTP/2 or HTTP/3 (typically over HTTPS). In a plain HTTP experiment, HTTP/1.1 is most commonly observed.
Observation Table
| Parameter | Observed Value |
|---|---|
| Source IP (GET) | ________________ |
| Destination IP (GET) | ________________ |
| Accept | ________________ |
| Accept-Language | ________________ |
| Accept-Encoding | ________________ |
| Accept-Charset | ________________ |
| URL | ________________ |
| User-Agent | ________________ |
| Source IP (Response) | ________________ |
| Destination IP (Response) | ________________ |
| Status Code | ________________ |
| Last Modified | ________________ |
| Content Length | ________________ |
| GET Timestamp | ________________ |
| Response Timestamp | ________________ |
| Response Time | ________________ |
| HTTP Version | ________________ |
Result
The HTTP communication between a client and a web server was successfully captured and analyzed using Wireshark. The HTTP GET request and corresponding HTTP response were examined to identify the source and destination IP addresses, accepted media types, language, encoding, user-agent information, status code, last modification time, content length, response time, and HTTP version. This experiment demonstrates how HTTP operates using the request-response model and how Wireshark can be used to inspect network traffic.
Additional Exercises
-
Repeat the experiment using different web browsers (Chrome, Firefox, and Edge) and compare the
User-Agentstrings. - Capture HTTP traffic from two different HTTP websites and compare their response headers.
-
Observe the differences between an HTTP
200 OKresponse and a404 Not Foundresponse. - Measure the response time for different websites and compare the results.
- Compare the HTTP headers sent by a desktop browser and a mobile browser (or browser emulation mode).
-
Investigate whether the
Accept-Charsetheader is present in different browsers and discuss why it may be omitted.
Comments
Post a Comment