Reader small image

You're reading from  Network Protocols for Security Professionals

Product typeBook
Published inOct 2022
Reading LevelIntermediate
PublisherPackt
ISBN-139781789953480
Edition1st Edition
Languages
Right arrow
Authors (2):
Yoram Orzach
Yoram Orzach
author image
Yoram Orzach

Yoram Orzach is a senior networks and networks security advisor, providing network design and network security consulting services to a range of clients. Having spent thirty years in network and information security, Yoram has worked as a network and security engineer across many verticals in roles ranging from a network engineer, security consultant, and instructor. Yoram has gained his B.Sc. from the Technion in Haifa, Israel. Yoram's experience is both with corporate networks; service providers and Internet service providers' networks. His customers are Motorola solutions, Elbit Systems, 888, Taboola, Bezeq, PHI Networks, Cellcom, Strauss group, and many other hi-tech companies.
Read more about Yoram Orzach

Deepanshu Khanna
Deepanshu Khanna
author image
Deepanshu Khanna

Deepanshu Khanna is a 29-year-old information security and cybercrime consultant and a pioneer in his country. The young and dynamic personality of Deepanshu has not only assisted him in handling information security and cybercrimes but also in creating awareness about these things. He's a hacker appreciated by the Indian government, including the Ministry of Home Affairs and Defence, police departments, and many other institutes, universities, globally renowned IT firms, magazines, and newspapers. He started his career by presenting a popular hack of GRUB at HATCon. He also conducted popular research in the fields of intruder detection software (IDS) and Advanced Intrusion Detection Environment (AIDE) and demonstrated MD5 collisions and buffer overflows, among other things. His work has been published in various magazines such as pentestmag, Hakin9, e-Forensics, SD Journal, and hacker5. He has been invited as a guest speaker to public conferences such as DEF CON, ToorCon, OWASP, HATCon, H1hackz, and many other universities and institutes.
Read more about Deepanshu Khanna

View More author details
Right arrow

Network forensics tools

Although there are various tools for network analysis, the best tool for network forensics is good old Wireshark. With Wireshark (and knowledge of your network and network protocols), you can identify suspicious patterns on the network based on a very simple principle – whatever you don't know can kill your network.

In Chapter 9, Using Behavior Analysis and Anomaly Detection, we will look into abnormal behaviors and suspicious behavior patterns.

Wireshark and packet capture tools

Wireshark, along with its command-line interface (CLI) programs – TShark for Windows and TCPdump for Linux – provides strong analyzing capabilities, and tools such as pyshark can be used as plugins for Python for this purpose.

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Network Protocols for Security Professionals
Published in: Oct 2022Publisher: PacktISBN-13: 9781789953480

Authors (2)

author image
Yoram Orzach

Yoram Orzach is a senior networks and networks security advisor, providing network design and network security consulting services to a range of clients. Having spent thirty years in network and information security, Yoram has worked as a network and security engineer across many verticals in roles ranging from a network engineer, security consultant, and instructor. Yoram has gained his B.Sc. from the Technion in Haifa, Israel. Yoram's experience is both with corporate networks; service providers and Internet service providers' networks. His customers are Motorola solutions, Elbit Systems, 888, Taboola, Bezeq, PHI Networks, Cellcom, Strauss group, and many other hi-tech companies.
Read more about Yoram Orzach

author image
Deepanshu Khanna

Deepanshu Khanna is a 29-year-old information security and cybercrime consultant and a pioneer in his country. The young and dynamic personality of Deepanshu has not only assisted him in handling information security and cybercrimes but also in creating awareness about these things. He's a hacker appreciated by the Indian government, including the Ministry of Home Affairs and Defence, police departments, and many other institutes, universities, globally renowned IT firms, magazines, and newspapers. He started his career by presenting a popular hack of GRUB at HATCon. He also conducted popular research in the fields of intruder detection software (IDS) and Advanced Intrusion Detection Environment (AIDE) and demonstrated MD5 collisions and buffer overflows, among other things. His work has been published in various magazines such as pentestmag, Hakin9, e-Forensics, SD Journal, and hacker5. He has been invited as a guest speaker to public conferences such as DEF CON, ToorCon, OWASP, HATCon, H1hackz, and many other universities and institutes.
Read more about Deepanshu Khanna