Book description
Grasp the basics of packet capture and analyze common protocols
Key Features
- Troubleshoot basic to advanced network problems using packet analysis
- Analyze common protocols and identify latency issues with Wireshark
- Explore ways to examine captures to recognize unusual traffic and possible network attacks
Book Description
Wireshark is a popular and powerful packet analysis tool that helps network administrators investigate latency issues and identify potential attacks.
Learn Wireshark provides a solid overview of basic protocol analysis and helps you to navigate the Wireshark interface, so you can confidently examine common protocols such as TCP, IP, and ICMP. The book starts by outlining the benefits of traffic analysis, takes you through the evolution of Wireshark, and then covers the phases of packet analysis. We'll review some of the command line tools and outline how to download and install Wireshark on either a PC or MAC. You'll gain a better understanding of what happens when you tap into the data stream, and learn how to personalize the Wireshark interface. This Wireshark book compares the display and capture filters and summarizes the OSI model and data encapsulation. You'll gain insights into the protocols that move data in the TCP/IP suite, and dissect the TCP handshake and teardown process. As you advance, you'll explore ways to troubleshoot network latency issues, and discover how to save and export files. Finally, you'll see how you can share captures with your colleagues using Cloudshark.
By the end of this book, you'll have a solid understanding of how to monitor and secure your network with the most updated version of Wireshark.
What you will learn
- Become familiar with the Wireshark interface
- Navigate commonly accessed menu options such as edit, view, and file
- Use display and capture filters to examine traffic
- Understand the Open Systems Interconnection (OSI) model
- Carry out deep packet analysis of the Internet suite: IP, TCP, UDP, ARP, and ICMP
- Explore ways to troubleshoot network latency issues
- Subset traffic, insert comments, save, export, and share packet captures
Who this book is for
This book is for network administrators, security analysts, students, teachers, and anyone interested in learning about packet analysis using Wireshark. Basic knowledge of network fundamentals, devices, and protocols along with an understanding of different topologies will be beneficial.
Table of contents
- Title Page
- Copyright and Credits
- Dedication
- About Packt
- Contributors
- Preface
- Section 1: Traffic Capture Overview
-
Appreciating Traffic Analysis
- Reviewing packet analysis
- Recognizing who benefits from using packet analysis
- Identifying where to use packet analysis
- Outlining when to use packet analysis
- Getting to know Wireshark
- Summary 
- Questions
- Using Wireshark NG
- Installing Wireshark on a PC or macOS
- Exploring the Wireshark Interface
- Section 2: Getting Started with Wireshark
- Tapping into the Data Stream
- Personalizing the Interface
- Using Display and Capture Filters
-
Outlining the OSI Model
- Comprehending the OSI model
- Discovering the purpose, protocols, and PDUs
- Exploring the encapsulation process
- Demonstrating frame formation in Wireshark
- Summary
- Questions
- Section 3: The Internet Suite TCP/IP
- Decoding TCP and UDP
- Managing TCP Connections
- Analyzing IPv4 and IPv6
- Discovering ICMP
- Understanding ARP
- Section 4: Working with Packet Captures
- Troubleshooting Latency Issues
- Subsetting, Saving, and Exporting Captures
- Using CloudShark for Packet Analysis
-
Assessment
- Chapter 1: Appreciating Traffic Analysis
- Chapter 2: Using Wireshark NG
- Chapter 3: Installing on a PC or macOS
- Chapter 4: Exploring the Wireshark Interface
- Chapter 5: Tapping into the Data Stream
- Chapter 6: Personalizing the Interface
- Chapter 7: Using Display and Capture Filters
- Chapter 8: Outlining the OSI Model
- Chapter 9: Decoding TCP and UDP
- Chapter 10: Managing TCP Connections
- Chapter 11: Analyzing IPv4 and IPv6
- Chapter 12: Discovering ICMP
- Chapter 13: Understanding ARP
- Chapter 14: Troubleshooting Latency Issues
- Chapter 15: Subsetting, Saving, and Exporting Captures
- Chapter 16:Using CloudShark for Packet Analysis
- Other Books You May Enjoy
Product information
- Title: Learn Wireshark - Fundamentals of Wireshark
- Author(s):
- Release date: August 2019
- Publisher(s): Packt Publishing
- ISBN: 9781789134506
You might also like
video
Wireshark Fundamentals
Nearly 5 Hours of Expert Video Instruction The Wireshark Fundamentals LiveLessons video training course offers nearly …
book
Learn Wireshark - Second Edition
Expertly analyze common protocols such as TCP, IP, and ICMP, along with learning how to use …
book
Wireshark Essentials
Get up and running with Wireshark to analyze network packets and protocols effectively In Detail This …
video
Network Analysis Using Wireshark 3
Wireshark is an open-source network protocol analyzer. It is the world's leading packet analyzer when it …