Packet analysis tools conventionally present capture data through tabular packet lists, constraining the analyst to a sequential view that obscures the relational structure of network communication. This paper presents Galaxy Tracer, a browser-native packet capture exploration system in which the default interface is an interactive three-dimensional network topology rather than a packet list. Hosts appear as spatially positioned nodes, conversations as edges, and protocol groupings as visually distinct clusters. A synchronized packet list remains available as a secondary view, sharing filter state with the topology so that structural and tabular inspection function as one continuous workflow. The system parses PCAP and PCAPNG formats, dissects over 90 protocols, and renders the topology through Three.js. The paper argues that the third spatial dimension is not merely aesthetic but analytically meaningful: it reveals density, clustering, host centrality, and communication scale that are difficult to perceive in list-only tools.
翻译:传统的包分析工具通常通过表格化的数据包列表呈现捕获数据,这种设计将分析人员限制在顺序视图中,从而模糊了网络通信的关系结构。本文提出Galaxy Tracer,一种浏览器原生的数据包捕获探索系统,其默认界面是交互式三维网络拓扑图而非数据包列表。主机呈现为空间定位的节点,会话呈现为边,协议分组则呈现为视觉上可区分的簇。系统同时提供同步的数据包列表作为辅助视图,该列表与拓扑图共享过滤状态,使得结构分析与表格检查融合为连续的工作流程。该系统支持解析PCAP和PCAPNG格式,可解析超过90种协议,并通过Three.js实现拓扑渲染。本文论证了第三空间维度不仅具有美学价值,更具有分析意义:它能揭示密度分布、聚类特征、主机中心性及通信规模等难以在纯列表工具中感知的网络特性。