Wireshark for Network Forensics: An Essential Guide for It and Cloud Professionals
暫譯: Wireshark 網路取證:IT 與雲端專業人士的必備指南
Nainar, Nagendra Kumar, Panda, Ashish
相關主題
商品描述
With the advent of emerging and complex technologies, traffic capture and analysis play an integral part in the overall IT operation. This book outlines the rich set of advanced features and capabilities of the Wireshark tool, considered by many to be the de-facto Swiss army knife for IT operational activities involving traffic analysis. This open-source tool is available as CLI or GUI. It is designed to capture using different modes, and to leverage the community developed and integrated features, such as filter-based analysis or traffic flow graph view.
You'll start by reviewing the basics of Wireshark, and then examine the details of capturing and analyzing secured application traffic such as SecureDNS, HTTPS, and IPSec. You'll then look closely at the control plane and data plane capture, and study the analysis of wireless technology traffic such as 802.11, which is the common access technology currently used, along with Bluetooth. You'll also learn ways to identify network attacks, malware, covert communications, perform security incident post mortems, and ways to prevent the same.
The book further explains the capture and analysis of secure multimedia traffic, which constitutes around 70% of all overall internet traffic. Wireshark for Network Forensics provides a unique look at cloud and cloud-native architecture-based traffic capture in Kubernetes, Docker-based, AWS, and GCP environments.
What You'll Learn
- Review Wireshark analysis and network forensics
- Study traffic capture and its analytics from mobile devices
- Analyze various access technology and cloud traffic
- Write your own dissector for any new or proprietary packet formats
- Capture secured application traffic for analysis
Who This Book Is For
IT Professionals, Cloud Architects, Infrastructure Administrators, and Network/Cloud Operators
商品描述(中文翻譯)
隨著新興和複雜技術的出現,流量捕獲和分析在整體 IT 操作中扮演著不可或缺的角色。本書概述了 Wireshark 工具的豐富先進功能和能力,許多人認為它是進行流量分析的事實上瑞士軍刀。這個開源工具可用於命令行介面(CLI)或圖形使用者介面(GUI)。它設計用於以不同模式進行捕獲,並利用社群開發和整合的功能,例如基於過濾器的分析或流量流圖視圖。
您將首先回顧 Wireshark 的基本知識,然後檢查捕獲和分析安全應用流量的細節,例如 SecureDNS、HTTPS 和 IPSec。接著,您將仔細研究控制平面和數據平面的捕獲,並研究無線技術流量的分析,例如 802.11,這是目前常用的接入技術,還有 Bluetooth。您還將學習識別網路攻擊、惡意軟體、隱蔽通信的方法,進行安全事件的事後分析,以及防止相同事件發生的方法。
本書進一步解釋了安全多媒體流量的捕獲和分析,這約佔所有互聯網流量的 70%。《Wireshark for Network Forensics》提供了對基於雲和雲原生架構的流量捕獲在 Kubernetes、基於 Docker、AWS 和 GCP 環境中的獨特視角。
您將學到的內容:
- 回顧 Wireshark 分析和網路取證
- 研究來自行動裝置的流量捕獲及其分析
- 分析各種接入技術和雲流量
- 為任何新的或專有的封包格式編寫自己的解碼器
- 捕獲安全應用流量以進行分析
本書適合對象:
IT 專業人員、雲架構師、基礎設施管理員以及網路/雲操作員
作者簡介
Ashish Panda is a technical leader with Cisco Systems. He has 18+ years of rich experience on network design, operation and troubleshooting with various large enterprises and service provider networks throughout the world. He is a speaker at various Cisco internal and external events
作者簡介(中文翻譯)
Nagendra Kumar Nainar (CCIE#20987) 是思科客戶體驗(CX)組織的首席工程師(前身為 TAC),專注於企業客戶。他是超過 130 項專利申請的共同發明人,涵蓋虛擬化/容器技術等不同技術。他是多篇互聯網 RFC、各種互聯網草案和 IEEE 論文的共同作者。Nagendra 也與思科出版社和 Packt 出版社等知名出版商共同撰寫了多本技術書籍。他是北卡羅來納州立大學的客座講師,並在不同的網絡論壇上擔任演講者。
Ashish Panda 是思科系統的技術領導者。他在網絡設計、運營和故障排除方面擁有超過 18 年的豐富經驗,曾與全球各大企業和服務提供商網絡合作。他是多個思科內部和外部活動的演講者。