Get in Touch

Course Outline

Network Analysis Foundations

  1. Core concepts of the OSI reference model and TCP/IP networking.
  2. Overview of troubleshooting methodologies and essential tools.
  3. Introduction to the Wireshark environment.
  4. Defining Wireshark: features, portable versions, and available resources.
  5. Anatomy of the Wireshark GUI: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
  6. Internal architecture and processing flow; understanding the limitations of what Wireshark can and cannot detect.
  7. Overview of supported protocols and dissectors.
  8. Configuring preferences and settings, both globally and per profile.
  9. Understanding time-based values.
  10. Practical lab exercises.

Initiating Traffic Capture

  1. Key considerations before beginning a capture session.
  2. The role of Promiscuous mode.
  3. Implementing capture filters.
  4. Defining automatic stop conditions.
  5. Configuring remote capture sessions.
  6. Practical lab exercises.

Traffic Analysis: Methodologies and Tooling

  1. Developing a structured analysis checklist.
  2. Leveraging built-in features: name resolution, color coding, marking packets, ignoring noise, adding comments, and utilizing time references and shifts.
  3. Interpreting the Expert System output.
  4. Accessing contextual options via Right-Click menus.
  5. Interpreting data through reference patterns and understanding the impact of OS/driver offload features.
  6. Exporting and saving analysis results.
  7. Lab exercises and real-world case studies.

Traffic Analysis: Advanced Tools and Approaches

  1. Refining traffic views: Creating Display filters (including "in-flight" filters and macros) and following data streams.
  2. Conducting quantitative analysis.
    1. Reviewing predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
    2. Performing protocol-specific deep dives (e.g., TCP Stream Graphs).
    3. Utilizing advanced custom statistics with the I/O Graph tool.
    4. Visualizing data flows.

Traffic Analysis: Protocol Deep Dive

  1. Data-Link Layer focus: Ethernet II.
  2. Network Layer focus: IPv4.
  3. Transport Layer focus: TCP and UDP.
    1. Diagnosing packet loss and recovery mechanisms.
    2. Identifying Previous segment lost and Out-of-Order Segments events.
    3. Analyzing Duplicate ACKs and Fast Retransmissions.
    4. Investigating TCP Retransmissions.
    5. Detecting Zero Window, Window changes, and other window-related anomalies.
  4. Application Layer focus: HTTP and FTP.
  5. Lab exercises and applied case studies.

Assessing Common Network Performance Issues

  1. Identifying root causes of performance degradation.
  2. Analyzing packet loss impacts.
  3. Addressing bandwidth constraints using a layered measurement approach.
  4. Evaluating latency: measuring end-to-end delays and visualizing results.
  5. Practical lab exercises.
  6. Command-line utilities for Wireshark:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
    2. Utility tools: editcap, mergecap, capinfos, and text2pcap.

Advanced Concepts

  1. Constructing advanced filters and using grouped I/O statistics.
  2. Course summary and Q&A session.

Requirements

1. Proficiency in the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Foundational knowledge of Unix/Linux operating systems, including UNIX terminal usage, directory structures, file and directory management (listing, creating, navigating, copying, moving, and removing), redirection, pipes, and process management (viewing suspended and background processes).

Hardware & Software Requirements: 1. Hardware: A minimum of 16GB RAM and 60GB of available free disk space. 2. Operating System: Ubuntu Linux is recommended. If used, the following utilities must be installed: ip, iperf, and ipcalc. 3. Software: The Wireshark application (available at https://www.wireshark.org/download.html).

Ensure all software and tools are updated to their latest stable releases.

 35 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories