How does Wireshark identify a TCP packet's protocol as HTTP?

Viewed 1491

Port number equals to 80 is obviously not a sufficient condition. Is it a necessary condition that Wireshark has found a request message or response message in application layer payload?

1 Answers
Related