Packet Analysis
Wireshark
Wireshark
is the world’s most popular packet analyzer widely used by professionals in
industry for network troubleshooting, analysis, software and protocol development,
as well as for educational purposes (Banerjee et al., 2010). Some notable
features of Wireshark include the following:
- · Live
captures of packets
- · Displayable,
detailed packet protocol information
- · Ability
to open and save captured packet data
- · Filter
and search packets based on certain criteria
- · Protocol
decoders (dissectors) (Lamping & Warnicke, 2004)
Wireshark
is a free, open-source tool that runs on a variety of computing platforms such
as Windows, OS X, Linux, and Unix.
[Wireshark packet captures] Retrieved from
https://www.wireshark.org/docs/wsug_html_chunked/ChapterIntroduction.html
Banerjee,
U., Vashishtha, A., & Saxena, M. (2010). Evaluation of the Capabilities of
WireShark as a tool for Intrusion Detection. International Journal of
computer applications, 6(7), 1-5.
Cloudfare.
(n.d.). What is a packet? | Network packet definition. Cloudfare Networking
Basics. Retrieved February 25, 2025 from https://www.cloudflare.com/learning/network-layer/what-is-a-packet/
Lamping,
U., & Warnicke, E. (2004). Wireshark user's guide. Interface, 4(6),
1.
Sikos, L. F. (2020). Packet analysis for network forensics: A comprehensive survey. Forensic Science International: Digital Investigation. 32, 2666-2817. https://doi.org/10.1016/j.fsidi.2019.200892.
Comments
Post a Comment