000 02440nam a22001697a 4500
999 _c6841
_d6841
020 _a978-1484290002
082 _a005.8
_bK96w
100 _aNagendra Kumar Nainar
245 _aWireshark for Network Forensics
_bAn Essential Guide for IT and Cloud Professionals
250 _a1a. EdiciĆ³n
260 _aBangalore, Karnataka, India
_bApress
_c2023
300 _a271 p.
505 _aTable of Contents About the authors About the contributor About the technical reviewer Acknowledgments Introduction Chapter 1: Wireshark Primer Chapter 2: Packet Capture and Analysis Chapter 3: Capturing Secured Application Traffic for Analysis Chapter 4: Capturing Wireless Traffic for Analysis Chapter 5: Multimedia Packet Capture and Analysis Chapter 6: Cloud and Cloud-Native Traffic Capture Chapter 7: Bluetooth Packet Capture and Analysis Chapter 8: Network Analysis and Forensics Chapter 9: Understanding and Implementing Wireshark Dissectors Index
520 _aWith the advent of emerging and complex technologies, traffic capture and analysis play an integral part in the overall IT operation. This book outlines the rich set of advanced features and capabilities of the Wireshark tool, considered by many to be the de-facto Swiss army knife for IT operational activities involving traffic analysis. This open-source tool is available as CLI or GUI. It is designed to capture using different modes, and to leverage the community developed and integrated features, such as filter-based analysis or traffic flow graph view. You'll start by reviewing the basics of Wireshark, and then examine the details of capturing and analyzing secured application traffic such as SecureDNS, HTTPS, and IPSec. You'll then look closely at the control plane and data plane capture, and study the analysis of wireless technology traffic such as 802.11, which is the common access technology currently used, along with Bluetooth. You'll also learn waysto identify network attacks, malware, covert communications, perform security incident post mortems, and ways to prevent the same. The book further explains the capture and analysis of secure multimedia traffic, which constitutes around 70% of all overall internet traffic. Wireshark for Network Forensics provides a unique look at cloud and cloud-native architecture-based traffic capture in Kubernetes, Docker-based, AWS, and GCP environments.
866 _a2
942 _cBK