UMBC Training Centers logo

Fundamentals of Packet Analysis

 

Course Description | Outline | Information Security Training | IT Training

Course Outline

Module 00: TCP/IP Review

  • OSI vs Internet Model
  • Physical and Logical Addresses
  • Services and Ports
  • Domain Name System
  • Routing

Module 01: The Protocols

  • Link Layer
  •     Ethernet
  •     Address Resolution Protocol
  • Network Layer
  •     Internet Protocol
  •     Internet Control Message Protocol
  • Transport Layer
  •     Transmission Control Protocol
  •     User Datagram Protocol
  • Application Layer
  • Dynamic Host Configuration Protocol
  • Domain Name System
  • Hypertext Transfer Protocol

Module 02: Basic tcpdump

  • Capture and read files
  • Command line options
  • Filters: hosts, ports and protocols

Module 03: Advanced tcpdump

  • Advanced expressions and primitives
  • Qualifers
  • Expression combinations
  • Offsets and specific byte identification

Module 04: Basic tshark

  • Installing tshark
  • Capture versus display filters
  • Capture and read files
  • Apply basic capture filters
  • Apply basic display filters

Module 05: Advanced tshark

  • Creating customized capture filters
  • The role and use of profiles
  • Ring buffers, file size, and duration
  • Mergecap, editcap, and capinfo

Module 06: Practical Exercise

  • An all day team exercise to analyze packet captures from a victim network and to provide a detailed analysis of findings