Course Outline
Overview of Network Analysis
- Essential concepts regarding the OSI reference model and TCP/IP networking architectures.
- Methodologies and utilities utilized for network troubleshooting.
- Foundational introduction to Wireshark capabilities.
- Definition of Wireshark; deployment via portable versions; access to supplemental resources for government analysts.
- Structure of the Wireshark graphical user interface: Packet List pane, Details pane, Packet Bytes pane, and Status Bar.
- System architecture and packet processing workflows. Limitations regarding observability within Wireshark.
- Supported network protocols and dissector mechanisms.
- Application of global and profile-specific preferences and configurations.
- Interpretation of time values in capture data.
- Practical laboratory exercises.
Traffic Capture Procedures
- Pre-capture considerations and prerequisites.
- Configuration of promiscuous mode for comprehensive packet acquisition.
- Implementation of capture filters.
- Definition of automatic stop criteria.
- Procedures for remote capture operations.
- Practical laboratory exercises.
Traffic Analysis: Tools and Approaches
- Standard analysis checklist.
- Utilization of analytical features: name resolution, color coding, packet marking, filtering by exclusion, commenting, time references, and time shifting.
- Understanding the function and output of the Expert System.
- Navigating configuration options via right-click contextual menus.
- Data interpretation using reference patterns; assessment of impacts from OS/driver offloading features.
- Procedures for saving analysis results.
- Practical laboratory exercises and case study reviews.
Traffic Analysis: Tools and Approaches (Continued)
- Traffic filtering techniques: creation of display filters (including macros) and stream following.
- Quantitative analysis methods.
- Descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
- Protocol-specific analysis, such as TCP Stream Graphs.
- Advanced custom statistics utilizing the I/O Graph tool.
- Data flow visualization techniques.
Traffic Analysis: Protocol Examination
- Data-Link Layer: Ethernet II frame analysis.
- Network Layer: IPv4 header inspection.
- Transport Layer: TCP and UDP protocol examination.
- Evaluation of packet loss and recovery mechanisms.
- Detection of lost previous segments and out-of-order segment events.
- Analysis of duplicate acknowledgments and fast retransmission triggers.
- Assessment of TCP retransmission issues.
- Identification of zero window conditions, window size changes, and related flow control problems.
- Application Layer: HTTP and FTP protocol analysis.
- Practical laboratory exercises and case study reviews.
Traffic Analysis: Common Network Performance Issues
- Identification of root causes for performance degradation.
- Assessment of packet loss.
- Evaluation of bandwidth constraints using a layered measurement approach.
- Latency analysis: end-to-end latency assessment and visualization.
- Practical laboratory exercises.
- Command-line utilities (Wireshark toolkit):
- tshark (terminal-based capture), dumpcap, rawshark, and tcpdump.
- Editcap, mergecap, capinfos, and text2pcap for file manipulation and information retrieval.
Advanced Topics
- Complex filtering techniques and grouped I/O statistics.
- Course summary and question-and-answer session.
Requirements
1. Proficiency in the ISO OSI Reference Model as defined by ITU-T X.200, along with a comprehensive understanding of the TCP/IP protocol stack.
2. Fundamental operational knowledge of Unix/Linux operating systems, including terminal navigation, directory management (creation, deletion, and traversal), file operations (copying, moving, and removal), stream redirection, pipe utilization, and process monitoring for both suspended and background tasks.
System Requirements
1. Hardware: A minimum of 16GB RAM and at least 60GB of available disk storage.
2. Operating System: Ubuntu Linux is recommended. Required software packages include ip, iperf, and ipcalc.
3. Software: Wireshark network analyzer (https://www.wireshark.org/download.html).
All specified components must be updated to their most recent stable releases for government compliance.
Testimonials (3)
practical case studies
Kamil - P4 Sp. z o.o.
Course - Basic Network Troubleshooting Using Wireshark
knowledge of the instructor
Grzegorz - Centrum Informatyki Resortu Finansow
Course - Network Troubleshooting with Wireshark
Many exercises, good knowladge