Course Outline
Overview of Network Analysis
- Fundamentals of the OSI reference model and TCP/IP networking.
- Diagnosis tools and methodological approaches.
- Introduction to Wireshark.
- What is Wireshark? Portable versions and available resources.
- Wireshark interface layout: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
- System architecture and processing workflows. Limitations of what Wireshark can reveal.
- Supported protocols and dissectors.
- Preferences and configuration settings, both global and profile-specific.
- Handling time values.
- Practical lab exercises.
Traffic Capture
- Pre-capture considerations.
- Promiscuous mode operation.
- Implementing capture filters.
- Setting automatic stop conditions.
- Performing remote captures.
- Practical lab exercises.
Traffic Analysis: Tools and Methodologies
- Establishing an analysis checklist.
- Leveraging features such as name resolution, color coding, marking, filtering, annotation, and time reference management.
- Interpreting the Expert System output.
- Utilizing right-click context options.
- Data interpretation, reference patterns, and the impact of OS/driver offload features.
- Exporting and saving analysis results.
- Lab exercises and case studies.
Traffic Analysis: Tools and Methodologies (Continued)
- Traffic filtering: Display filters (creating dynamic filters, using macros) and stream following.
- Quantitative analysis.
- Basic descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
- Protocol-specific analysis (e.g., TCP Stream Graphs).
- Advanced custom statistics via I/O Graph.
- Visualizing data flows.
Traffic Analysis: Protocol Deep Dive
- Data-Link Layer: Examination of Ethernet II.
- Network Layer: IPv4 analysis.
- Transport Layer: TCP and UDP protocols.
- Packet loss and recovery mechanisms.
- Handling lost previous segments and Out-of-Order events.
- Duplicate ACKs and Fast Retransmissions.
- Analyzing TCP Retransmissions.
- Windowing issues: Zero Window, window adjustments, and related problems.
- Application Layer: HTTP and FTP protocols.
- Practical lab exercises and case studies.
Traffic Analysis: Common Challenges in Performance Assessment
- Identifying root causes of performance degradation.
- Investigating packet loss.
- Bandwidth constraints and a layered measurement approach.
- Latency assessment: End-to-end evaluation and visualization techniques.
- Practical lab exercises.
- Wireshark command-line utilities:
- tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
- editcap, mergecap, capinfos, and text2pcap
Advanced Topics
- Complex filtering techniques and grouped I/O statistics.
- Course summary and Q&A session.
Requirements
1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.
2. Fundamental understanding of Unix/Linux operating systems, including terminal usage, directory structures, file management (listing, creating, moving, and deleting), redirection, piping, and process management (including suspended and background tasks).
Hardware & Software Requirements
1. Hardware: Minimum 16GB RAM and at least 60GB of available disk space.
2. Operating System: Ubuntu Linux is recommended. Ensure the following utilities are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).
All components should be updated to their latest stable versions.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge