Wireshark Network Traffic Analysis Certificate for Ablieiev Pavlo
Certificate ID:
783599
Authentication Code:
28e79
Certified Person Name:
Ablieiev Pavlo
Trainer Name:
Paweł Radziszewski
Duration Days:
3
Duration Hours:
21
Course Name:
Wireshark Network Traffic Analysis
Course Date:
2 October 2024 09:00 to 14 October 2024 16:00
Course Outline:
Day 1
Network analysis overview
- OSI reference model and TCP/IP networks essentials.
- Troubleshooting tools, methodologies.
- Introduction to Wireshark
- What is Wireshark? Portable Wireshark. Resources.
- Wireshark GUI structure: Panes (Packet List, Details, Packet Bytes), Status Bar, ... .
- Architecture and processing flow. What and why cannot be seen with Wireshark?
- Supported protocols. Dissectors.
- Preferences and configurations; global and profile specific.
- Time values.
- Lab exercises.
Day 2
Capture traffic
- Things to consider before start.
- Promiscuous mode.
- Capture filters.
- Automatic stop criteria.
- Remote capture.
- Lab exercises.
Traffic analysis: tools and approaches
- Analysis checklist.
- Using features: name resolution, colorization, marking, ignoring, commenting, using time references, time shifts, etc.
- Understanding Expert System.
- Accessing options through Right-Click functionality.
- Interpretation (reference patterns), OS/driver Offload features impact.
- Saving results.
- Lab exercises and case studies.
Day 3
Traffic analysis: tools and approaches (cont.)
- Filtering traffic: Display filters (preparing "in-flight" filters, macros), following stream.
- Quantitative analysis.
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packets Lengths, IP-specific.
- Protocol specific analysis (e.g.: TCP Stream Graphs).
- Advanced custom statistics with I/O Graph.
- Flow visualization.
Day 4
Traffic analysis: protocols
- Data-Link Layer: Ethernet II.
- Network Layer: IPv4.
- Transport Layer: TCP, UDP.
- Packet loss and recovery.
- Previous segment lost and Out-of-Order Segments events.
- Duplicate ACKs and Fast Retransmissions.
- TCP Retransmissions.
- Zero Window, Window changes and other window problems.
- Application layer: HTTP, FTP.
- Lab exercises and case studies.
Day 5
Traffic analysis: common issues in network performance assessment
- Cause of performance problems.
- Packet loss.
- Bandwidth issues. Layered approach to measurement.
- Latency: assessing end to end latency, visualization.
- Lab exercises.
- (Wireshark) command-line tools:
- tshark (terminal-based wireshark) / dumpcap / rawshark, tcpdump
- editcap, mergecap, capinfos, text2pcap.
Advanced topics
- Advanced filters, grouped iostats.
- Summary and Q&A.