Analysis of HTTP Protocol using Wireshark


Experiment 

Study and Analysis of HTTP Protocol Using Wireshark


Aim

To capture and analyze HTTP packets using Wireshark and study the structure of HTTP request and response messages.


Objectives

After completing this experiment, students will be able to:

  • Understand the working of the HTTP protocol.
  • Capture network packets using Wireshark.
  • Apply protocol filters in Wireshark.
  • Analyze HTTP GET requests and HTTP response messages.
  • Identify important HTTP header fields.
  • Calculate the response time of a web request.
  • Understand client-server communication using HTTP.

Theory

HTTP (Hypertext Transfer Protocol)

HTTP is an application layer protocol used for communication between a web browser (client) and a web server. It follows the request-response model.

When a user enters a website address in the browser:

  1. The browser sends an HTTP Request to the server.
  2. The server processes the request.
  3. The server returns an HTTP Response containing the requested webpage.

HTTP generally uses

  • Port Number : 80
  • Transport Protocol : TCP

Note: Most modern websites use HTTPS (HTTP Secure) on port 443. Since HTTPS encrypts the data, the HTTP contents are not visible in Wireshark. For this experiment, use a website that supports plain HTTP (for example, http://neverssl.com).


HTTP Communication

           HTTP Request
Browser ---------------------> Web Server

HTTP Response
Browser <--------------------- Web Server

HTTP Request Format

GET /index.html HTTP/1.1
Host: example.com
User-Agent: Mozilla/5.0
Accept: text/html
Accept-Language: en-US
Accept-Encoding: gzip, deflate
Connection: keep-alive

HTTP Response Format

HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 5120
Last-Modified: Tue, 10 Jun 2025 08:30:00 GMT

<HTML DATA>

Software Required

  • Wireshark
  • Google Chrome / Mozilla Firefox / Microsoft Edge
  • Internet Connection

Procedure

Step 1

Open Wireshark.


Step 2

Select the active network interface (Wi-Fi or Ethernet).

Click

Start Capturing Packets

Step 3

Clear the browser cache.

For Chrome

Settings
→ Privacy and Security
→ Clear Browsing Data

Clear Cached Images and Files.


Step 4

Open the browser.

Visit an HTTP website such as

http://neverssl.com

or

http://httpforever.com

Wait until the webpage loads completely.


Step 5

Return to Wireshark.

Stop packet capture.

Capture
→ Stop

Step 6

In the filter box enter

http

Click Apply.

Only HTTP packets will now be displayed.


Understanding the Packet List

You will observe packets similar to

No.    Protocol    Info

25 HTTP GET / HTTP/1.1
26 HTTP HTTP/1.1 200 OK

The first packet is the HTTP Request.

The second packet is the HTTP Response.


Packet Analysis

Click the first GET packet.

Expand

Hypertext Transfer Protocol

You will see

GET / HTTP/1.1

Host:

User-Agent:

Accept:

Accept-Language:

Accept-Encoding:

Answer the Following Questions


(a) Find the Source IP Address and Destination IP Address of the First GET Message

Expand

Internet Protocol Version 4

Example

Source Address

192.168.1.15

Destination Address

34.117.59.81

Answer

Source IP Address

192.168.1.15

Destination IP Address

34.117.59.81

Explanation

  • Source IP is the client's computer.
  • Destination IP is the web server.

(b) Determine the Medium Format, Language, Encoding and Character Set Accepted by the Client

Expand the HTTP request.

Observe the following fields.

Accept

Accept:
text/html,
application/xhtml+xml,
application/xml

This specifies the media formats accepted by the browser.

Answer

Medium Format

text/html
application/xhtml+xml
application/xml

Accept-Language

Example

Accept-Language:

en-US,en;q=0.9

Answer

Language

English (United States)
English

Accept-Encoding

Example

gzip, deflate, br

Answer

Encoding

gzip
deflate
brotli (br)

Accept-Charset

Older browsers may display

Accept-Charset

UTF-8

Modern browsers usually omit this field because UTF-8 is assumed by default.

Answer

Character Set

UTF-8 (if present)

Otherwise

Not explicitly specified

(c) Determine the URL and User Agent

Host Field

Example

Host

neverssl.com

Request URI

/

Hence

Complete URL

http://neverssl.com/

User-Agent

Example

Mozilla/5.0

Windows NT 10.0

AppleWebKit

Chrome

Answer

Browser

Google Chrome

Operating System

Windows 10

Rendering Engine

AppleWebKit

(d) Determine the Source and Destination IP Address of the First Response Message

Click

HTTP/1.1 200 OK

Expand

Internet Protocol

Example

Source

34.117.59.81

Destination

192.168.1.15

Notice that the addresses are reversed.

Answer

Source

Server

Destination

Client

(e) Determine the Status Code

Expand

Hypertext Transfer Protocol

Example

HTTP/1.1 200 OK

Status Code

200

Meaning

Request Successful

Common HTTP Status Codes

CodeMeaning
200OK
301Moved Permanently
302Redirect
304Not Modified
400Bad Request
401Unauthorized
403Forbidden
404Not Found
500Internal Server Error

(f) Determine When the HTML File Was Last Modified

Locate

Last-Modified

Example

Last-Modified

Tue, 10 Jun 2025 08:30:00 GMT

This indicates the last modification time of the webpage on the server.


(g) Determine the Content-Length

Locate

Content-Length

Example

Content-Length

5120

Meaning

The HTML page size is

5120 bytes

(h) Calculate the Time Taken to Receive the Response

Observe

GET Packet

Time

3.420001 seconds

Response Packet

Time

3.468945 seconds

Therefore

Response Time

3.468945
−
3.420001

=

0.048944 seconds

Approximately

49 milliseconds

Formula

Response Time

=

Response Timestamp

−

GET Timestamp

(i) Determine the HTTP Version

Observe the first line of the GET request.

Example

GET / HTTP/1.1

Hence

HTTP Version

HTTP/1.1

Some browsers communicating over newer protocols may instead use HTTP/2 or HTTP/3 (typically over HTTPS). In a plain HTTP experiment, HTTP/1.1 is most commonly observed.


Observation Table

ParameterObserved Value
Source IP (GET)________________
Destination IP (GET)________________
Accept________________
Accept-Language________________
Accept-Encoding________________
Accept-Charset________________
URL________________
User-Agent________________
Source IP (Response)________________
Destination IP (Response)________________
Status Code________________
Last Modified________________
Content Length________________
GET Timestamp________________
Response Timestamp________________
Response Time________________
HTTP Version________________

Result

The HTTP communication between a client and a web server was successfully captured and analyzed using Wireshark. The HTTP GET request and corresponding HTTP response were examined to identify the source and destination IP addresses, accepted media types, language, encoding, user-agent information, status code, last modification time, content length, response time, and HTTP version. This experiment demonstrates how HTTP operates using the request-response model and how Wireshark can be used to inspect network traffic.


Additional Exercises

  1. Repeat the experiment using different web browsers (Chrome, Firefox, and Edge) and compare the User-Agent strings.
  2. Capture HTTP traffic from two different HTTP websites and compare their response headers.
  3. Observe the differences between an HTTP 200 OK response and a 404 Not Found response.
  4. Measure the response time for different websites and compare the results.
  5. Compare the HTTP headers sent by a desktop browser and a mobile browser (or browser emulation mode).
  6. Investigate whether the Accept-Charset header is present in different browsers and discuss why it may be omitted.

Comments

Popular posts from this blog

Networks Lab PCCSL507 Semester 5 KTU CS 2024 Scheme - Dr Binu V P

Study of whois Command

Study and Use of ifconfig Command