Professional Documents
Culture Documents
by T.S.R.K. Prasad
References / Acknowledgements
Laura Chappells Introduction to Ethereal, part 1 of 2 Introduction to Ethereal, part 2 of 2 (will be made available on the course site) tcpdump (same as Wireshark) capture filters and Wireshark display filters available at http://packetlife.net/library/cheat-sheets/
References
Optional Readings
[nCAP] L. Deri, nCap: Wire-speed Packet Capture and Transmission (ntop.org) Steven McCanne and Van Jacobson, The BSD Packet Filter: A New Architecture for User-level Packet Capture, USENIX 1993. Francesco Fusco and Luca Deri, High Speed Network Traffic Analysis with Commodity Multi-core Systems, IMC2010.
[BPF]
[Fusco]
Optional Reading
Presentation Overview
Advanced Features Wireshark Filters Wireshark UI
Placement Strategies
Introduction
Lecture Outline
Presentation Overview
Advanced Features Wireshark Filters Wireshark UI
Placement Strategies
Introduction
Lecture Outline
Applications of Wireshark
network administrators use it to troubleshoot network problems network security engineers use it to examine security problems developers use it to debug protocol implementations people use it to learn network protocol internals
Introduction Applications
Features of Wireshark
Available for UNIX and Windows. Capture live packet data from a network interface. Display packets with very detailed protocol information. Open and Save packet data captured. Import and Export packet data from and to a lot of other capture programs.
Introduction Features
Filter packets on many criteria. Search for packets on many criteria. Colorize packet display based on filters. Create various statistics. ... and a lot more!
Introduction Limitations
Presentation Overview
Advanced Features Wireshark Filters Wireshark UI
Placement Strategies
Introduction
Lecture Outline
Placement Strategies
Presentation Overview
Advanced Features Wireshark Filters Wireshark UI
Placement Strategies
Introduction
Lecture Outline
Wireshark Main UI
Capture Interfaces
UI Capture Interfaces
Capture Options
Capture everyones packets Limit capture packet size Capture interface Capture filter
Options to store capture data in files Capture stop triggers Name and Address Resolution
UI Capture Options
In Capture Options
Capture Data
Wireshark menu
Summary Window
Decode Window
Hex Window
UI Capture Data
Summary Window
Packet number Packet Source (Name / Address) Highest Protocol Packet Summary
Relative timestamp
UI Summary Window
Decode Window
Capture details for the packet
MAC header
UI Decode Window
Decode Window 2
Network Header
Transport Header
UI Decode Window
Tells you something about the network. Probably first thing to look at when in trouble.
UI Protocol Hierarchy
Analyze Menu
UI Analyze Menu
Statistics Menu
Statistical information about the captured packets. The most useful menu in Wireshark.
UI Statistics Menu
Telephony Menu
With right equipment, Wireshark can also look into the telephone network. Govt. permit required to purchase the equipment.
UI Telephony Menu
UI Preferences
UI Coloring Rules
UI End Points
UI End Points
Presentation Overview
Advanced Features Wireshark Filters Wireshark UI
Placement Strategies
Introduction
Lecture Outline
Filters
Display Filter
Display filter Expression builder for display filter
Presentation Overview
Advanced Features Wireshark Filters Wireshark UI
Placement Strategies
Introduction
Lecture Outline
Wireshark IO Graphs