Announcing the SANS 5th Annual Log Management Survey: A Leading Source for Actionable Data on Key Issues and Trends.
Please take a moment to complete our survey.
the most trusted source for computer security training, certification and research


select a course
Toronto, ON - May 10 - 16, 2008
Global Information Assurance Certification

The information presented is priceless!
-Nehal Parmar, North Fork Bank

SECURITY 556

Comprehensive Packet Analysis

Saturday, May 10, 2008 : 9am - 5pm
Guy Bruneau, IPSS Inc.
6 CPE Credits Per Day

Knowing how to decode network traffic is a skill requirement for any serious network or information security administrator. Being able to decode the bits and bytes that represent mission-critical networks will give you the skills to identify malicious activity, troubleshoot network failures, and analyze other desirable or undesirable network events.

This class will give you the skills necessary to decode network traffic with open-source tools available for Unix and Windows systems. Students will learn advance pcap packet filtering methods to decode and manipulate network traffic using tcpdump and use Wireshark to extract files (pictures, documents, executable, etc) from datastream for malware recovery, incident response and forensics analysis. You'll be able to use these new skills to analyze current or future network protocols and gain a better understanding of your network traffic. The tools covered in this class are: Windump/TCPdump, Wireshark, Mergecap, Unix file command and an Hex Editor.

Students are expected to be generally familiar with TCP/IP at the theoretical level. If you are not familiar with TCP/IP, we recommend you read the following documents before attending:

  • Who should attend this course?
    • Incident Response analysts, firewall and network administrators looking to learn advance packet decoding skills
    • Analysts looking to learn advance techniques in packet analysis
    • Analysts wanting to learn how to recover and analyze files from packet streams
    • Network administrators and operations professionals seeking a deeper understanding of network analysis techniques
  • Topics Covered
    • TCP/IP basics
    • TCPdump from basic to advance
    • Writing simple to complex TCPdump Filters
    • TCPdump exercises
    • Introduction to Ngrep
    • Ngrep exercises
    • Wireshark as an analyst and forensic tool
    • Introduction to tshark and mergecap
    • Filters in Wireshark
    • Using Wireshark for troubleshooting VoIP
    • Using Wireshark to carve out files from pcap data (malware, pictures, documents, etc)
    • Wireshark exercises
    • Troubleshooting network and applications
Author Statement

If you have not yet attended Security 502: Perimeter Protection In-Depth or Security 503: Intrusion Detection In-Depth and want some solid skills to analyze and troubleshoot traffic flowing through your network, this is the course for you. This course is designed to teach the core skills to read and understand various types of traffic that you will see in a corporate network with TCPdump and Wireshark. About one third of the course is spent on exercises to reinforce the material taught in the class. We are confident the skills you will learn here will put into practice the day you get back to the office.

- Guy Bruneau and Jonathan Ham