Documente Academic
Documente Profesional
Documente Cultură
Application Behavior
Chris Greer
NETWORK ANALYST
@packetpioneer www.packetpioneer.com
st
h
ns
Servers
Client
Network
Frame Encapsulation
Data
Data TCP
Data TCP IP
FRAME (Packet)
Packet Anatomy: Ethernet
IP Header
Packet Anatomy: TCP
TCP Header
Packet Anatomy: Payload
Payload
st
h
ns
Demo
Dissect a Packet in Wireshark
- Use the Lab 1 Trace File
Identifying Client Conversations
Identifying Client Conversations
Servers
Client
Network
Using Wireshark Statistics
Using Wireshark Statistics
st
h
ns
Demo
Analyze Client Conversations
- Use the Lab 2 Trace File
Creating and Applying Display Filters
Filter out the Madness!
Two Ways to Filter
Demo
Creating and Applying Display Filters
- Use the Lab 3 Trace File
Top 10 Wireshark Filters for Analysis
Common Wireshark Filters
ip.addr == 10.0.0.1
tcp.port == 443
tcp contains pluralsight
dns or tcp
ip.addr == 10.0.0.1 and tcp
!(arp or stp or cdp or lldp)
sip or rtp
tcp.analysis.flags && !tcp.analysis.window_update
tcp.flags.reset == 1
tcp.time_delta > 1
st
h
ns
Demo
Top Display Filters
- Learn how to add them as buttons
Analyzing End User and
Application Behavior
Typical Client Flow
Servers
Client
Network
Mapping Application Flow
Databases
App Tier
st
h
ns