Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems, 3/e
暫譯: 實用封包分析:使用 Wireshark 解決現實世界的網路問題,第三版

Chris Sanders

買這商品的人也買了...

商品描述

Wireshark is the world's most popular network sniffer that makes capturing packets easy, but it won't be much help if you don't have a solid foundation in packet analysis.

Practical Packet Analysis, 3rd Edition will show you how to make sense of your PCAP data and let you start troubleshooting the problems on your network. This third edition is updated for Wireshark 2.0.5 and IPV6, making it the definitive guide to packet analysis and a must for any network technician, administrator, or engineer. This updated version includes two new chapters that will teach you how to use the powerful command-line packet analyzers tcpdump and TShark as well as how to read and reference packet values using a packet map.

Practical Packet Analysis will introduce you to the basics of packet analysis, starting with how networks work and how packets travel along the wire. Then you'll move onto navigating packets and using Wireshark to capture and analyze packets. The book then covers common lower-layer and upper-layer protocols and provides you with real-world scenarios like Internet connectivity issues, how to capture social media traffic, and fighting a slow network.

You'll learn how to:

  • Monitor your network in real-time and tap live network communications
  • Recognize common network protocols including TCP, IPv4 and IPv6, SMTP, and ARP
  • Build customized capture and display filters to quickly navigate through large numbers of packets
  • Troubleshoot and resolve common network problems like loss of connectivity, DNS issues, and sluggish speeds with packet analysis
  • Understand how modern exploits and malware behave at the packet level
  • Carve out data in a packet to retrieve the actual files sent across the network
  • Graph traffic patterns to visualize the data flowing across your network
  • Use advanced Wireshark features to understand confusing captures
  • Build statistics and reports to help you better explain technical network information to non-techies

Whether you're a budding network analyst in need of a headfirst dive into packet analysis or an experienced administrator searching for new tricks, look no further than the third edition of Practical Packet Analysis.

商品描述(中文翻譯)

Wireshark 是全球最受歡迎的網路封包擷取工具,使得擷取封包變得簡單,但如果您沒有扎實的封包分析基礎,它將無法提供太多幫助。

《實用封包分析(第三版)》將教您如何理解您的 PCAP 數據,並讓您開始排除網路上的問題。這一版已更新至 Wireshark 2.0.5 和 IPV6,成為封包分析的權威指南,對於任何網路技術人員、管理員或工程師來說都是必備的。這個更新版本包含兩個新章節,將教您如何使用強大的命令列封包分析工具 tcpdump 和 TShark,以及如何使用封包地圖來閱讀和參考封包值。

《實用封包分析》將介紹封包分析的基礎,從網路如何運作以及封包如何在網路中傳輸開始。接著,您將學習如何導航封包並使用 Wireshark 擷取和分析封包。該書還涵蓋了常見的下層和上層協定,並提供了現實世界的情境,例如網際網路連接問題、如何擷取社交媒體流量以及解決緩慢的網路問題。

您將學習如何:

- 實時監控您的網路並攔截即時網路通訊
- 辨識常見的網路協定,包括 TCP、IPv4 和 IPv6、SMTP 和 ARP
- 建立自訂的擷取和顯示過濾器,以快速導航大量封包
- 通過封包分析排除和解決常見的網路問題,如連接中斷、DNS 問題和速度緩慢
- 理解現代攻擊和惡意軟體在封包層級的行為
- 從封包中提取數據,以檢索實際在網路上傳送的檔案
- 繪製流量模式,以可視化流經您網路的數據
- 使用進階的 Wireshark 功能來理解複雜的擷取
- 建立統計數據和報告,以幫助您更好地向非技術人員解釋技術網路資訊

無論您是需要深入了解封包分析的初學網路分析師,還是尋找新技巧的經驗豐富的管理員,《實用封包分析(第三版)》都是您的最佳選擇。