Course Outline
Day 1
Overview of Network Analysis for Government
- Essentials of the OSI reference model and TCP/IP networks.
- Troubleshooting methodologies and tools for government.
- Introduction to Wireshark for government.
- Understanding Wireshark: portable versions, resources, and key features.
- Wireshark GUI structure: Packet List, Details, Packet Bytes panes, Status Bar, and more.
- Architecture and processing flow of Wireshark. Limitations on what can be seen with Wireshark for government.
- Supported protocols and dissectors in Wireshark for government.
- Configuring preferences and settings: global and profile-specific configurations.
- Managing time values in Wireshark for government.
- Hands-on lab exercises.
Day 2
Capturing Traffic for Government
- Pre-capture considerations for government networks.
- Utilizing promiscuous mode in network capture for government.
- Applying capture filters for targeted data collection for government.
- Setting automatic stop criteria for efficient data management for government.
- Conducting remote captures for government networks.
- Hands-on lab exercises.
Traffic Analysis: Tools and Approaches for Government
- Developing a traffic analysis checklist for government.
- Utilizing Wireshark features: name resolution, colorization, marking, ignoring, commenting, time references, and time shifts.
- Understanding the Expert System in Wireshark for government.
- Accessing options through right-click functionality for efficient analysis for government.
- Interpreting results with reference patterns and understanding OS/driver offload features for government.
- Saving and documenting analysis results for government.
- Hands-on lab exercises and case studies for government.
Day 3
Traffic Analysis: Tools and Approaches (Continued) for Government
-
Filtering traffic in Wireshark for government:
- Using display filters, preparing "in-flight" filters, and macros.
- Following network streams for detailed analysis for government.
-
Quantitative Analysis in Wireshark for government:
- Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific analysis.
- Protocol-specific analysis, such as TCP Stream Graphs for government.
- Advanced custom statistics with I/O Graph for government.
- Flow visualization techniques for government.
Day 4
Traffic Analysis: Protocols for Government
- Data-Link Layer analysis: Ethernet II for government.
- Network Layer analysis: IPv4 for government.
-
Transport Layer analysis for government:
- Identifying and resolving packet loss and recovery issues for government.
- Analyzing previous segment lost and out-of-order segments events for government.
- Understanding duplicate ACKs and fast retransmissions for government.
- Investigating TCP retransmissions for government.
- Addressing zero window, window changes, and other window problems for government.
- Application Layer analysis: HTTP and FTP for government.
- Hands-on lab exercises and case studies for government.
Day 5
Traffic Analysis: Common Issues in Network Performance Assessment for Government
- Identifying causes of performance problems in government networks.
- Analyzing packet loss for government.
- Addressing bandwidth issues with a layered approach to measurement for government.
- Assessing and visualizing end-to-end latency for government.
- Hands-on lab exercises for government.
-
Command-line tools in Wireshark for government:
- Using tshark, dumpcap, rawshark, and tcpdump for command-line analysis for government.
- Utilizing editcap, mergecap, capinfos, and text2pcap for advanced data manipulation for government.
Advanced Topics in Network Analysis for Government
- Developing advanced filters and grouped I/O statistics for government.
- Summary and Q&A session for government.
Requirements
Testimonials (3)
Quality of explanation of program operation and analysis of various cases.
Krzysztof - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
trainer listen to participants
Bartosz - ATOS PGS sp. z o.o.
Course - Advanced Network Troubleshooting Using Wireshark
Trainer is well prepared and dedicated in making us understand. Well done.