Using the Endpoints tool from the Statistics menu

In this recipe we will learn how to get statistics on endpoints information of the captured data.

Getting ready

Start Wireshark, click on Statistics.

How to do it...

To view the endpoint statistics, follow these steps:

  1. From the statistics menu, click on Endpoints.
    How to do it...
  2. The following window will come up:
    How to do it...
  3. In this window, you will be able to see layers 2 and 3 and 4 endpoints, which are Ethernet, IP, and TCP or UDP.

How it works...

It simply gives statistics on all the endpoints that Wireshark has discovered. It could be any of the situations here:

  • Few Ethernet endpoints (these are MAC addresses) with many IP end nodes (these are IP addresses): This will be the case where, for example, we have a router that sends/receives packets from many remote devices, and what we will see is the MAC address of the router and many IP addresses coming/going through it.
  • Few IP end nodes with many TCP end nodes: this will be the case for many TCP connections per host. It can be a regular operation of a server with many connections, and it can also be a kind of attack that comes through the network (for example, an SYN attack).

There's more...

Here you see an example for a capture file taken from a network center, and what we can get from it.

In the following screenshot, we see an internal network with four HP servers and a single Cisco router. We can see this from the first part of the MAC address that is resolved to vendor names:

There's more...

When we choose to see the endpoints under IPv4: 191, we see many endpoints coming from the networks 192.168.10.0, 192.168.30.0, and also other networks.

There's more...
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.145.179.252