Book description
Get up and running with Wireshark to analyze network packets and protocols effectively
In Detail
This book introduces the Wireshark network analyzer to IT professionals across multiple disciplines.
It starts off with the installation of Wireshark, before gradually taking you through your first packet capture, identifying and filtering out just the packets of interest, and saving them to a new file for later analysis. The subsequent chapters will build on this foundation by covering essential topics on the application of the right Wireshark features for analysis, network protocols essentials, troubleshooting, and analyzing performance issues. Finally, the book focuses on packet analysis for security tasks, command-line utilities, and tools that manage trace files.
Upon finishing this book, you will have successfully added strong Wireshark skills to your technical toolset and significantly increased your value as an IT professional.
What You Will Learn
- Discover how packet analysts view networks and the role of protocols at the packet level
- Capture and isolate all the right packets to perform a thorough analysis using Wireshark's extensive capture and display filtering capabilities
- Use the optimal timestamp displays, packet marking and coloring, and protocol-level settings for effective analysis of packets
- Select and configure the appropriate Wireshark features and functions for the analysis task at hand
- Troubleshoot connectivity and functionality issues in your network
- Analyze and report the leading causes of poor application performance
- Analyze packets to detect and identify malicious traffic and security threats
- Leverage the Wireshark command-line utilities for high performance or scripted analysis activities
Table of contents
-
Wireshark Essentials
- Table of Contents
- Wireshark Essentials
- Credits
- About the Author
- About the Reviewers
- www.PacktPub.com
- Preface
- 1. Getting Acquainted with Wireshark
-
2. Networking for Packet Analysts
- The OSI model – why it matters
- IP networks and subnets
- Switching and routing packets
- WAN links
- Wireless networking
- Summary
-
3. Capturing All the Right Packets
- Picking the best capture point
- Test Access Ports and switch port mirroring
- Capturing interfaces, filters, and options
- Verifying a good capture
- Saving the bulk capture file
- Isolating conversations of interest
- Using the Conversations window
- Wireshark display filters
- Filter Expression Buttons
- Following TCP/UDP/SSL streams
- Marking and ignoring packets
- Saving the filtered traffic
- Summary
- 4. Configuring Wireshark
-
5. Network Protocols
- The OSI and DARPA reference models
- Transport layer protocols
- Application layer protocols
- Summary
-
6. Troubleshooting and Performance Analysis
- Troubleshooting methodology
- Troubleshooting connectivity issues
- Troubleshooting functional issues
-
Performance analysis methodology
- Top five reasons for poor application performance
- Summary
- 7. Packet Analysis for Security Tasks
- 8. Command-line and Other Utilities
- Index
Product information
- Title: Wireshark Essentials
- Author(s):
- Release date: October 2014
- Publisher(s): Packt Publishing
- ISBN: 9781783554638
You might also like
book
Wireshark 2 Quick Start Guide
Protect your network as you move from the basics of the Wireshark scenarios to detecting and …
book
Learn Wireshark - Fundamentals of Wireshark
Grasp the basics of packet capture and analyze common protocols Key Features Troubleshoot basic to advanced …
video
Wireshark Fundamentals
Nearly 5 Hours of Expert Video Instruction The Wireshark Fundamentals LiveLessons video training course offers nearly …
book
Nmap Essentials
Harness the power of Nmap, the most versatile network port scanner on the planet, to secure …