Get in Touch

Course Outline

Overview of Network Analysis

  1. Foundations of the OSI reference model and TCP/IP networks.
  2. Overview of troubleshooting tools and methodologies.
  3. Introduction to Wireshark.
  4. Understanding Wireshark: Portable versions and available resources.
  5. Wireshark GUI layout: Panes (Packet List, Details, Packet Bytes), Status Bar, and more.
  6. System architecture and processing flow: Identifying what Wireshark cannot observe and the reasons why.
  7. Supported protocols and dissectors.
  8. Configurations and preferences: Global settings and profile-specific adjustments.
  9. Understanding time values within captures.
  10. Practical laboratory exercises.

Traffic Capture

  1. Considerations prior to initiating a capture.
  2. Promiscuous mode.
  3. Implementing capture filters.
  4. Defining automatic stop criteria.
  5. Performing remote captures.
  6. Practical laboratory exercises.

Traffic Analysis: Tools and Approaches

  1. The analysis checklist.
  2. Leveraging features: Name resolution, colour coding, marking, ignoring, adding comments, and managing time references and shifts.
  3. Interpreting the Expert Information system.
  4. Utilising context-sensitive options via right-click functionality.
  5. Data interpretation: Recognising reference patterns and the impact of OS/driver Offload features.
  6. Exporting and saving analysis results.
  7. Practical exercises and case studies.

Traffic Analysis: Tools and Approaches (Continued)

  1. Traffic filtering: Display filters (preparing dynamic filters, macros) and following streams.
  2. Quantitative analysis.
    1. Basic predefined descriptive statistics and summaries: Capture Properties, Protocol Hierarchy, Conversations, Endpoints, Packet Lengths, and IP-specific metrics.
    2. Protocol-specific analysis (e.g., TCP Stream Graphs).
    3. Advanced custom statistics using I/O Graphs.
    4. Flow visualisation techniques.

Traffic Analysis: Protocols

  1. Data-Link Layer: Ethernet II.
  2. Network Layer: IPv4.
  3. Transport Layer: TCP and UDP.
    1. Packet loss and recovery mechanisms.
    2. Events involving lost previous segments and Out-of-Order Segments.
    3. Duplicate ACKs and Fast Retransmissions.
    4. TCP Retransmissions.
    5. Zero Window, window size changes, and other window-related issues.
  4. Application Layer: HTTP and FTP.
  5. Practical exercises and case studies.

Traffic Analysis: Common Issues in Network Performance Assessment

  1. Root causes of performance degradation.
  2. Diagnosing packet loss.
  3. Bandwidth constraints: A layered approach to measurement.
  4. Latency: Assessing end-to-end latency and visualisation methods.
  5. Practical laboratory exercises.
  6. Wireshark command-line utilities:
    1. tshark (terminal-based Wireshark), dumpcap, rawshark, and tcpdump.
    2. editcap, mergecap, capinfos, and text2pcap.

Advanced Topics

  1. Advanced filtering techniques and grouped I/O statistics.
  2. Summary review and Q&A session.

Requirements

1. Proficiency with the ISO OSI Reference Model (ITU-T X.200) and the TCP/IP protocol stack.

2. Fundamental understanding of Unix/Linux operating systems: UNIX terminal usage, directory structures, file and directory listing, directory creation, navigation, file manipulation (copying, moving, deleting), input/output redirection, piping, and process management (including suspended and background processes).



Hardware & Software Requirements 1. Hardware: A minimum of 16GB of RAM and at least 60GB of available disk space. 2. Operating System: Ubuntu Linux is recommended. Users of this system should ensure the following utilities are installed: ip, iperf, and ipcalc. 3. Software: The Wireshark application (available at https://www.wireshark.org/download.html).

All components should be updated to the latest stable release versions.

 35 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories