Wireshark/Advanced
From charlesreid1
Advanced Stuff
Endpoints and Conversations
See Wireshark/Conversation Analysis page
Protocol Statistics
You can open Statistics > Protocol Hierarchy to see information about what protocols are used in what amounts.
This can be useful if you are trying to determine "normal" behavior for a network, and then trying to determine if a particular day's traffic is an outlier and why.
By looking at a network's traffic protocol statistics, you can learn a lot about that network. Example: IT department will have admin protocols like ICMP or SNMP. Ordering department will use lots of SMTP. Interns will use WoW.
Name Resolution
To convert from a MAC address to an IP address is name resolution using the ARP protocol.
To convert from IP to Human-readable domain name uses DNS protocol.
Traffic
Wireshark IO graphs show the measure of traffic in a given space over time. By changing the time resolution you get very different pictures of the data.
Case in point: the rather boring 1-second resolution:
versus the much more interesting 10-minute resolution:
| Wireshark a Swiss-army knife for analyzing networks, network traffic, and pcap files.
Wireshark · Category:Wireshark Packet Analysis · Wireshark/Advanced Wireshark/HTTPS · Wireshark/Traffic Analysis · Wireshark/Conversation Analysis · Wireshark/Protocol Analysis Working with SSL/TLS/HTTPS: MITM Labs/Decrypting HTTPS Traffic by Obtaining Browser SSL Session Info · MITM Labs/Decrypting HTTPS Traffic with Private Key File
|