241
7
nEtWork monItorIng WIth
WIrEShark and WIndumP
In this chapter we focus on the use of two network monitoring programs.
Each program provides users with a comprehensive tool to obtain insight
into what is occurring on a network. e first tool we examine is the pro-
gram Wireshark. We then turn our attention to the program WinDump.
7.1 Wireshark
Wireshark can be downloaded for Windows-based computers at
the uniform resource locater (URL) address of www.wireshark.org/
download. is program includes a significant amount of valuable
features, to include the ability to inspect hundreds of protocols, cap-
ture data on the fly as well as perform an offline analysis, use a variety
of filters to reduce data to your field of interest, perform an analysis
of V ...