Get in Touch
 Duration 35 hours

Course Outline

Overview of Network Analysis

  1. Fundamentals of the OSI reference model and TCP/IP networking.
  2. Diagnosis tools and methodological approaches.
  3. Introduction to Wireshark.
  4. What is Wireshark? Portable versions and available resources.
  5. Wireshark interface layout: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
  6. System architecture and processing workflows. Limitations of what Wireshark can reveal.
  7. Supported protocols and dissectors.
  8. Preferences and configuration settings, both global and profile-specific.
  9. Handling time values.
  10. Practical lab exercises.

Traffic Capture

  1. Pre-capture considerations.
  2. Promiscuous mode operation.
  3. Implementing capture filters.
  4. Setting automatic stop conditions.
  5. Performing remote captures.
  6. Practical lab exercises.

Traffic Analysis: Tools and Methodologies

  1. Establishing an analysis checklist.
  2. Leveraging features such as name resolution, color coding, marking, filtering, annotation, and time reference management.
  3. Interpreting the Expert System output.
  4. Utilizing right-click context options.
  5. Data interpretation, reference patterns, and the impact of OS/driver offload features.
  6. Exporting and saving analysis results.
  7. Lab exercises and case studies.


Traffic Analysis: Tools and Methodologies (Continued)

  1. Traffic filtering: Display filters (creating dynamic filters, using macros) and stream following.
  2. Quantitative analysis.
    1. Basic descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics via I/O Graph.
    4. Visualizing data flows.

Traffic Analysis: Protocol Deep Dive

  1. Data-Link Layer: Examination of Ethernet II.
  2. Network Layer: IPv4 analysis.
  3. Transport Layer: TCP and UDP protocols.
    1. Packet loss and recovery mechanisms.
    2. Handling lost previous segments and Out-of-Order events.
    3. Duplicate ACKs and Fast Retransmissions.
    4. Analyzing TCP Retransmissions.
    5. Windowing issues: Zero Window, window adjustments, and related problems.
  4. Application Layer: HTTP and FTP protocols.
  5. Practical lab exercises and case studies.

Traffic Analysis: Common Challenges in Performance Assessment

  1. Identifying root causes of performance degradation.
  2. Investigating packet loss.
  3. Bandwidth constraints and a layered measurement approach.
  4. Latency assessment: End-to-end evaluation and visualization techniques.
  5. Practical lab exercises.
  6. Wireshark command-line utilities:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump
    2. editcap, mergecap, capinfos, and text2pcap

Advanced Topics

  1. Complex filtering techniques and grouped I/O statistics.
  2. Course summary and Q&A session.

Requirements

1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Fundamental understanding of Unix/Linux operating systems, including terminal usage, directory structures, file management (listing, creating, moving, and deleting), redirection, piping, and process management (including suspended and background tasks).

Hardware & Software Requirements
1. Hardware: Minimum 16GB RAM and at least 60GB of available disk space.
2. Operating System: Ubuntu Linux is recommended. Ensure the following utilities are installed: ip, iperf, and ipcalc.
3. Software: The Wireshark application (https://www.wireshark.org/download.html).

All components should be updated to their latest stable versions.

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories