Wireshark Workbook 1: Practice, Challenges, and Solutions
暫譯: Wireshark 實作手冊 1:練習、挑戰與解決方案

Chappell, Laura, Aragon, James

  • 出版商: Laura Chappell University
  • 出版日期: 2019-11-11
  • 售價: $2,370
  • 貴賓價: 9.5$2,252
  • 語言: 英文
  • 頁數: 364
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1893939642
  • ISBN-13: 9781893939646
  • 相關分類: Wireshark
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

相關主題

商品描述

Wireshark is the world's most popular network analyzer solution. Used for network troubleshooting, forensics, optimization and more, Wireshark is considered one of the most successful open source projects of all time.

Laura Chappell has been involved in the Wireshark project since its infancy (when it was called Ethereal) and is considered the foremost authority on network protocol analysis and forensics using Wireshark.

This book consists of 16 labs and is based on the format Laura introduced to trade show audiences over ten years ago through her highly acclaimed "Packet Challenges." This book gives you a chance to test your knowledge of Wireshark and TCP/IP communications analysis by posing a series of questions related to a trace file and then providing Laura's highly detailed step-by-step instructions showing how Laura arrived at the answers to the labs.

Book trace files and blank Answer Sheets can be downloaded from this book's supplement page (see https: //www.chappell-university.com/books).

Lab 1: Wireshark Warm-Up
Objective: Get Comfortable with the Lab Process. Completion of this lab requires many of the skills you will use throughout this lab book. If you are a bit shaky on any answer, take time when reviewing the answers to this lab to ensure you have mastered the necessary skill(s).

Lab 2: Proxy Problem
Objective: Examine issues that relate to a web proxy connection problem.

Lab 3: HTTP vs. HTTPS
Objective: Analyze and compare HTTP and HTTPS communications and errors using inclusion and field existence filters.

Lab 4: TCP SYN Analysis
Objective: Filter on and analyze TCP SYN and SYN/ACK packets to determine the capabilities of TCP peers and their connections.

Lab 5: TCP SEQ/ACK Analysis
Objective: Examine and analyze TCP sequence and acknowledgment numbering and Wireshark's interpretation of non-sequential numbering patterns.

Lab 6: You're Out of Order
Objective: Examine Wireshark's process of distinguishing between out-of-order packets and retransmissions and identify mis-identifications.

Lab 7: Sky High
Objective: Examine and analyze traffic captured as a host was redirected to a malicious site.

Lab 8: DNS Warm-Up
Objective: Examine and analyze DNS name resolution traffic that contains canonical name and multiple IP address responses.

Lab 9: Hacker Watch
Objective: Analyze TCP connections and FTP command and data channels between hosts.

Lab 10: Timing is Everything
Objective: Analyze and compare path latency, name resolution, and server response times.

Lab 11: The News
Objective: Analyze capture location, path latency, response times, and keepalive intervals between an HTTP client and server.

Lab 12: Selective ACKs
Objective: Analyze the process of establishing Selective acknowledgment (SACK) and using SACK during packet loss recovery.

Lab 13: Just DNS
Objective: Analyze, compare, and contrast various DNS queries and responses to identify errors, cache times, and CNAME (alias) information.

Lab 14: Movie Time
Objective: Use various display filter types, including regular expressions (regex), to analyze HTTP redirections, end-of-field values, object download times, errors, response times and more.

Lab 15: Crafty
Objective: Practice your display filter skills using "contains" operators, ASCII filters, and inclusion/exclusion filters, while analyzing TCP and HTTP performance parameters.

Lab 16: Pattern Recognition
Objective: Focus on TCP conversations and endpoints while analyzing TCP sequence numbers, Window Scaling, keep-alive, and Selective Acknowledgment capabilities.

商品描述(中文翻譯)

Wireshark 是全球最受歡迎的網路分析解決方案。用於網路故障排除、取證、優化等,Wireshark 被認為是有史以來最成功的開源專案之一。

Laura Chappell 自 Wireshark 專案初期(當時稱為 Ethereal)便參與其中,並被視為使用 Wireshark 進行網路協定分析和取證的權威。

本書包含 16 個實驗室,基於 Laura 十多年前在貿易展上介紹的格式,該格式通過她備受讚譽的「封包挑戰」而聞名。本書讓您有機會通過一系列與追蹤檔案相關的問題來測試您對 Wireshark 和 TCP/IP 通訊分析的知識,然後提供 Laura 詳細的逐步指導,展示她如何得出實驗室的答案。

書中的追蹤檔案和空白答案表可以從本書的補充頁面下載(請參見 https://www.chappell-university.com/books)。

實驗室 1:Wireshark 熱身
目標:熟悉實驗室流程。完成此實驗室需要您在整本實驗室書中將使用的許多技能。如果您對任何答案有些不確定,請在檢查此實驗室的答案時花時間確保您已掌握必要的技能。

實驗室 2:代理問題
目標:檢查與網路代理連接問題相關的問題。

實驗室 3:HTTP 與 HTTPS
目標:使用包含和欄位存在過濾器分析和比較 HTTP 和 HTTPS 通訊及錯誤。

實驗室 4:TCP SYN 分析
目標:過濾和分析 TCP SYN 和 SYN/ACK 封包,以確定 TCP 對等方及其連接的能力。

實驗室 5:TCP SEQ/ACK 分析
目標:檢查和分析 TCP 序列和確認編號,以及 Wireshark 對非順序編號模式的解釋。

實驗室 6:您已超出順序
目標:檢查 Wireshark 區分亂序封包和重傳的過程,並識別錯誤識別。

實驗室 7:高空
目標:檢查和分析在主機被重定向到惡意網站時捕獲的流量。

實驗室 8:DNS 熱身
目標:檢查和分析包含標準名稱和多個 IP 地址響應的 DNS 名稱解析流量。

實驗室 9:駭客監控
目標:分析主機之間的 TCP 連接和 FTP 命令及數據通道。

實驗室 10:時機就是一切
目標:分析和比較路徑延遲、名稱解析和伺服器響應時間。

實驗室 11:新聞
目標:分析 HTTP 客戶端和伺服器之間的捕獲位置、路徑延遲、響應時間和保持連接間隔。

實驗室 12:選擇性確認
目標:分析建立選擇性確認(SACK)的過程,以及在封包丟失恢復期間使用 SACK。

實驗室 13:僅 DNS
目標:分析、比較和對比各種 DNS 查詢和響應,以識別錯誤、快取時間和 CNAME(別名)資訊。

實驗室 14:電影時間
目標:使用各種顯示過濾器類型,包括正則表達式(regex),分析 HTTP 重定向、欄位結束值、物件下載時間、錯誤、響應時間等。

實驗室 15:巧妙
目標:在分析 TCP 和 HTTP 性能參數時,使用「包含」運算符、ASCII 過濾器和包含/排除過濾器來練習您的顯示過濾器技能。

實驗室 16:模式識別
目標:在分析 TCP 序列號、窗口縮放、保持連接和選擇性確認能力時,專注於 TCP 對話和端點。