Nagendra Kumar Nainar and Ashish Panda

Wireshark for Network Forensics

An Essential Guide for IT and Cloud Professionals

Nagendra Kumar Nainar
North Carolina, NC, USA
Ashish Panda
Bangalore, Karnataka, India
ISBN 978-1-4842-9000-2e-ISBN 978-1-4842-9001-9
© Nagendra Kumar Nainar and Ashish Panda 2023
This work is subject to copyright. All rights are solely and exclusively licensed by the Publisher, whether the whole or part of the material is concerned, specifically the rights of translation, reprinting, reuse of illustrations, recitation, broadcasting, reproduction on microfilms or in any other physical way, and transmission or information storage and retrieval, electronic adaptation, computer software, or by similar or dissimilar methodology now known or hereafter developed.
The use of general descriptive names, registered names, trademarks, service marks, etc. in this publication does not imply, even in the absence of a specific statement, that such names are exempt from the relevant protective laws and regulations and therefore free for general use.
The publisher, the authors, and the editors are safe to assume that the advice and information in this book are believed to be true and accurate at the date of publication. Neither the publisher nor the authors or the editors give a warranty, expressed or implied, with respect to the material contained herein or for any errors or omissions that may have been made. The publisher remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.

This Apress imprint is published by the registered company APress Media, LLC, part of Springer Nature.

The registered company address is: 1 New York Plaza, New York, NY 10004, U.S.A.

Nagendra Kumar Nainar: I would like to dedicate this book to my late Chitappah Asokan who never failed to inspire me during my young age.

Ashish Panda: I would like to dedicate this book to my parents for making possible everything that I have in life and to my wife and daughter for all the encouragement and sacrifices.

Naren: I would like to dedicate my contribution to my father Manikandan and mother Kavithamani who dedicated their time to support and encourage me in making this contribution possible. I would also like to dedicate this to my loving sister Dhanya.

Introduction

Traffic capture and analysis is an integral part of the overall IT operation, and accordingly Wireshark is an essential skillset required for any IT operation team. This community developed and managed open source tool powers the operation team with the ability to dissect the traffic across the layers for security analysis and troubleshooting purposes. This book will help the readers gain essential knowledge about the Wireshark tool and how to use the same for capturing and analyzing various types of traffic.

The book starts by sprucing up the knowledge of the readers about the Wireshark architecture and its basic installation and use. Further, the book explains the use of this tool to capture the traffic in different unique scenarios. This explains helps the readers to capture the traffic from mobile devices, Bluetooth captures along with cloud and cloud-native environment. The book also explains the use of different cypher techniques to capture the keys and decode encrypted traffic for deep analysis. Overall, this book will help the readers to gain strong knowledge about the tool and its usage in different, latest technology scenarios.

Acknowledgments

Nagendra Kumar Nainar: First, I would like to thank my wife Lavanya and daughter Ananyaa for their patience and support not just during the time of this book authoring but always.

I would also like to thank my coauthor, mentee, and good friend Ashish Panda who shared the load with me writing the chapters. I would like to thank my other (high school) mentee Naren Manikandan for his enthusiasm and energy shown to engage and contribute to finish this book on time.

I would like to thank my good friend Arun Arunachalam for helping with details around dissector development. A very special thanks to Aditee Mirashi, Shonmirin PA, and other Apress publication crew for helping us get this book published on time.

Ashish Panda: I would like to thank my mentor and coauthor Nagendra who always encouraged and inspired me to take the road less traveled, including taking this project of authoring the book. Thanks also to Naren for all the contributions. His energy and enthusiasm at such a young age amaze me.

A big thanks to my wife Pallabi and daughter Akanksha for being my strength and support always. This wouldn’t have been possible without their patience and sacrifices.

I would like to thank all my friends who were by my side and supported me even during odd hours while writing this book. Also, I would like to thank the whole Apress team, especially Aditee and Shonmirin, who made sure that the book gets published on time.

Naren Manikandan: I would like to thank my history teacher Mr. Jefferson Guilford for inspiring me to think outside the box even in simple matters. I would also like to thank Nagendra Kumar Nainar for giving me this opportunity to exhibit my passion to the world.

Table of Contents
About the Authors
Nagendra Kumar Nainar

A photograph of Nagendra Kumar Nainar.

(CCIE#20987, CCDE#20190014) is a Principal Engineer with Cisco Customer Experience CX Organization, focusing on enterprise and service provider customers. He is the coinventor of more than 150 patent applications in different technologies including virtualization/container technologies. He is the coauthor of multiple Internet RFCs, various Internet drafts, and IEEE papers. Nagendra Kumar also coauthored multiple technical books with other publishers such as Cisco Press and Packt. He is a guest lecturer in North Carolina State University and a speaker in different network forums.
 
Ashish Panda

A photograph of Ashish Panda.

(CCIE#33270) is a Senior Technical Leader with Cisco Systems Customer Experience CX Organization primarily focused on handling complex service provider network design and troubleshooting escalations. He has 19+ years of rich experience in network design, operation, and troubleshooting with various large enterprises and service provider networks (ISP, satellite, MPLS, 5G, and cloud) worldwide. He is a speaker at various Cisco internal and external events and is very active in the network industry standard bodies.
 
About the Contributor
Naren Manikandan

A photograph of Naren Manikandan.

is a sophomore at Research Triangle High School, a voracious technology learner who is potentially working toward positively impacting the technology industry. His passion about technology inspired his mentor to involve him as a contributing author for this book. He is part of the First Robotics Competition (FRC) team leading the development of computer vision for robots that participates in international robotics competitions. Naren actively indulges in intraschool and interschool discussions and other industry technical meetups.
 
About the Technical Reviewer
Brahma Nath Pandey

A photograph of Brahma Nath Pandey.

is currently working as Vice President at Blackrock, one of the world’s leading financial institutions. He has extensive experience working in telecom, automobile, IOT, and finance domains. At Blackrock, he is leading a team of talented engineers in designing and implementing several critical data engineering projects. In his past organizations, he has designed and deployed Java-based distributed cloud-native autoscalable solution to the cloud. He got acquainted with Wireshark while working for InfoVista, using it to analyze SNMP packets being sent to and from an application.

Apart from his day job, he is a curious tech and science enthusiast whom you can find trying out new things. He has a keen interest in space and green technologies, and he loves playing chess.

 
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.17.74.227