Get in Touch

Course Outline

Overview of Network Analysis

  1. Essentials of the OSI reference model and TCP/IP networks.
  2. Troubleshooting tools and methodologies.
  3. Introduction to Wireshark
  4. Understanding Wireshark: Portable versions and available resources.
  5. Wireshark GUI layout: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
  6. Architecture and processing flow: limitations and invisible elements in Wireshark.
  7. Supported protocols and dissection methods.
  8. Preferences and configurations, both global and profile-specific.
  9. Handling time values.
  10. Lab exercises.

Capturing Traffic

  1. Pre-capture considerations.
  2. Promiscuous mode.
  3. Setting capture filters.
  4. Defining automatic stop criteria.
  5. Remote capture techniques.
  6. Lab exercises.

Traffic Analysis: Tools and Methodologies

  1. Analytical checklists.
  2. Leveraging features: name resolution, color-coding, marking, ignoring, commenting, and time references/shifts.
  3. Comprehending the Expert System.
  4. Accessing options via Right-Click functionality.
  5. Interpretation using reference patterns and the impact of OS/driver Offload features.
  6. Saving analysis results.
  7. Lab exercises and case studies.


Traffic Analysis: Tools and Methodologies (Continued)

  1. Filtering traffic: Display filters (preparing "in-flight" filters, macros) and following streams.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific data.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graph.
    4. Flow visualization.

Traffic Analysis: Protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP and UDP.
    1. Packet loss and recovery mechanisms.
    2. Events involving lost previous segments and Out-of-Order Segments.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window, window size changes, and other window-related issues.
  4. Application Layer: HTTP and FTP.
  5. Lab exercises and case studies.

Traffic Analysis: Common Issues in Network Performance Assessment

  1. Root causes of performance issues.
  2. Packet loss analysis.
  3. Bandwidth issues and layered measurement approaches.
  4. Latency: Assessing end-to-end latency and visualization techniques.
  5. Lab exercises.
  6. (Wireshark) command-line tools:
    1. tshark (terminal-based Wireshark) / dumpcap / rawshark, tcpdump
    2. editcap, mergecap, capinfos, text2pcap.

Advanced Topics

  1. Advanced filters and grouped iostats.
  2. Summary and Q&A session.

Requirements

1. Understanding of the ISO OSI Reference Model - ITU-T X.200 and the TCP/IP protocol stack.

2. Foundational knowledge of Unix/Linux operating systems: UNIX terminal usage, directory structure, listing files and directories, creating directories, navigating paths, copying, moving, and deleting files and directories, redirection, pipes, and managing suspended and background processes.

Hardware & Software
1. HW: Minimum 16GB of RAM and 60GB of free disk space.
2. OS: Ubuntu Linux OS is recommended. If used, ensure the following applications are installed: ip, iperf, ipcalc.
3. SW: Wireshark application (https://www.wireshark.org/download.html).

All components should be running the latest stable available releases.

 35 Hours

Testimonials (3)

Upcoming Courses

Related Categories