Learn Wireshark
暫譯: 學習 Wireshark
Bock, Lisa
- 出版商: Packt Publishing
- 出版日期: 2019-08-23
- 售價: $1,770
- 貴賓價: 9.5 折 $1,682
- 語言: 英文
- 頁數: 432
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1789134501
- ISBN-13: 9781789134506
-
相關分類:
Wireshark
-
其他版本:
Learn Wireshark - Second Edition
商品描述
Learn |
|
---|---|
About |
Wireshark is a popular and powerful packet analysis tool that helps network administrators investigate latency issues and identify potential attacks. Learn Wireshark provides a solid overview of basic protocol analysis and helps you to navigate the Wireshark interface, so you can confidently examine common protocols such as TCP, IP, and ICMP. The book starts by outlining the benefits of traffic analysis, takes you through the evolution of Wireshark, and then covers the phases of packet analysis. We’ll review some of the command line tools and outline how to download and install Wireshark on either a PC or MAC. You'll gain a better understanding of what happens when you tap into the data stream, and learn how to personalize the Wireshark interface. This Wireshark book compares the display and capture filters and summarizes the OSI model and data encapsulation. You'll gain insights into the protocols that move data in the TCP/IP suite, and dissect the TCP handshake and teardown process. As you advance, you'll explore ways to troubleshoot network latency issues, and discover how to save and export files. Finally, you'll see how you can share captures with your colleagues using Cloudshark. By the end of this book, you'll have a solid understanding of how to monitor and secure your network with the most updated version of Wireshark. |
Features |
|
商品描述(中文翻譯)
更多資訊
學習內容
- 熟悉 Wireshark 介面
- 導航常用的選單選項,如編輯、檢視和檔案
- 使用顯示和擷取過濾器來檢查流量
- 理解開放系統互連(Open Systems Interconnection, OSI)模型
- 執行網際網路協定的深度封包分析:IP、TCP、UDP、ARP 和 ICMP
- 探索排除網路延遲問題的方法
- 子集流量、插入註解、儲存、匯出和分享封包擷取
關於本書
Wireshark 是一款流行且強大的封包分析工具,幫助網路管理員調查延遲問題並識別潛在攻擊。
《學習 Wireshark》提供了基本協定分析的全面概述,並幫助您導航 Wireshark 介面,使您能夠自信地檢查常見協定,如 TCP、IP 和 ICMP。本書首先概述流量分析的好處,接著介紹 Wireshark 的演變,然後涵蓋封包分析的各個階段。我們將回顧一些命令列工具,並概述如何在 PC 或 MAC 上下載和安裝 Wireshark。您將更好地理解當您接入數據流時發生了什麼,並學習如何個性化 Wireshark 介面。本書比較了顯示和擷取過濾器,並總結了 OSI 模型和數據封裝。您將深入了解在 TCP/IP 套件中移動數據的協定,並剖析 TCP 握手和拆解過程。隨著進一步的學習,您將探索排除網路延遲問題的方法,並發現如何儲存和匯出檔案。最後,您將看到如何使用 Cloudshark 與同事分享擷取內容。
在本書結束時,您將對如何使用最新版本的 Wireshark 監控和保護您的網路有扎實的理解。
特色
- 使用封包分析排除基本到進階的網路問題
- 分析常見協定並使用 Wireshark 識別延遲問題
- 探索檢查擷取內容以識別異常流量和可能的網路攻擊的方法