ip.src == 1.1.1.1
ip.dst == 2.2.2.2
ip.addr == 3.3.3.3
tcp.port == 80
tcp.port <= 80
tcp.srcport == 80
tcp.dstport == 80
tcp.flags.syn == 1 //SYN置位报文
【Wireshark】抓包实战,图文详解TCP三次握手及四次挥手原理 https://fengyun.blog.csdn.net/article/details/144008146
wireshark tcp报文深度解析 https://blog.csdn.net/qq_40008325/article/details/130604148
WireShark过滤解析HTTP/TCP https://www.cnblogs.com/kxdblog/p/4203924.html
抓包分析 https://www.cnblogs.com/kxdblog/p/4202827.html