Network Security Packet Analysis

Wireshark is an efficient utility packed with an advanced set of features that assist security professionals in performing passive analysis of network traffic to identify and point out malicious packets and anomalies.

This chapter will guide you through how to use Wireshark to analyze security issues, such as analyzing malware traffic and footprinting attempts. We will cover the following topics:

  • Analyzing port scanning, footprinting, and attack/exploitation network traffic
  • Dissecting malicious ARP traffic
  • Analyzing brute force attacks
  • Inspecting malicious traffic
  • Creating display and capture filter signatures for malicious traffic

Using real-life scenarios simulated in a virtual network infrastructure, ...

Get Wireshark 2 Quick Start Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.