From charlesreid1

Revision as of 03:03, 20 January 2016 by Admin (talk | contribs)

Protocols

Another way to analyze traffic in Wireshark is to look at statistics about the protocol layer.

You can open Statistics > Protocol Hierarchy to see information about what protocols are used in what amounts.

This can be useful if you are trying to determine "normal" behavior for a network, and then trying to determine if a particular day's traffic is an outlier and why.

By looking at a network's traffic protocol statistics, you can learn a lot about that network. Example: IT department will have admin protocols like ICMP or SNMP. Ordering department will use lots of SMTP. Interns will use WoW.

Wireless Pcap

If you load a wireless pcap into Wireshark and click Statistics > Protocol Hierarchy, you might see something like this:

WirelessProtocolHierarchy.png