Curso Wireshark Network Analysis Specialization
24 horasVisão Geral
Curso Wireshark Network Analysis Specialization. Entre no mundo da análise avançada de redes com nosso curso de especialização Wireshark. Este Curso Wireshark Network Analysis Specialization, intensivo foi projetado para capacitar os participantes com as habilidades necessárias para desvendar as complexidades dos comportamentos de rede, gargalos de desempenho e possíveis vulnerabilidades de segurança. O treinamento enfatiza áreas-chave, como identificação de falhas de desempenho decorrentes da latência do caminho, identificação de dispositivos que descartam pacotes e validação da configuração ideal de hosts de rede. Ele vai um passo além para analisar dependências complexas, otimizar comportamentos de aplicativos e oferecer insights sobre as funcionalidades das redes TCP/IP.
No ambiente digital moderno, é fundamental compreender o comportamento e a segurança dos aplicativos durante os vários estágios. Este Curso Wireshark Network Analysis Specialization, aprimora técnicas para verificar a segurança do aplicativo durante momentos cruciais, como login, inicialização e transferência de dados. Os participantes também aprenderão a detectar anomalias no tráfego de rede, indicativas de hosts potencialmente comprometidos, e desenvolverão proficiência no uso de representações gráficas para relatar problemas como lentidão no desempenho do servidor, perdas de pacotes e congestionamento da rede. Ao final deste curso imersivo, os participantes terão se transformado em especialistas em análise de rede, adeptos de aproveitar o Wireshark para otimizar a saúde e a segurança da rede.
Publico Alvo
- Qualquer pessoa interessada em aprender a solucionar problemas e otimizar redes TCP/IP e analisar o tráfego de rede com o Wireshark, especialmente engenheiros de rede, especialistas em tecnologia da informação, analistas de segurança e aqueles que se preparam para o exame Wireshark Certified Network Analyst.
- Alunos com conhecimentos/capacidades pré-requisitos recomendados
- É bom ter um forte conhecimento prático da funcionalidade de dispositivos de interconexão (switch, roteador, NAT, por exemplo) e estar confortável com os elementos do conjunto de protocolos TCP/IP (ARP, TCP, UDP, IP, DHCP, ICMP, por exemplo) .
Pre-Requisitos
- Este é um curso para iniciantes. Nenhum conhecimento prévio sobre Wireshark é necessário
- Baixe e instale o Wireshark https://www.wireshark.org/#download .
Materiais
Inglês/Português/Lab PráticoConteúdo Programatico
Introduction to Network Analysis and Wireshark
- TCP/IP Analysis Checklist
- Top Causes of Performance Problems
- Get the Latest Version of Wireshark
- Capturing Traffic
- Opening Trace Files
- Processing Packets
- The Qt Interface Overview
- Using Linked Panes
- The Icon Toolbar
- Master the Intelligent Scrollbar
- The Changing Status Bar
- Right-Click Functionality
- General Analyst Resources
- Your First Task When You Leave Class
Learn Capture Methods and Use Capture Filters
- Analyze Switched Networks
- Walk-Through a Sample SPAN Configuration
- Analyze Full-Duplex Links with a Network TAP
- Analyze Wireless Networks
- USB Capture
- Initial Analyzing Placement
- Remote Capture Techniques
- Available Capture Interfaces
- Save Directly to Disk
- Capture File Configurations
- Limit Your Capture with Capture Filters
- Examine Key Capture Filters
Customize for Efficiency: Configure Your Global Preferences
- First Step: Create a Troubleshooting Profile
- Customize the User Interface
- Add Custom Columns for the Packet List Pane
- Set Your Global Capture Preferences
- Define Name Resolution Preferences
- Configure Individual Protocol Preference
Navigate Quickly and Focus Faster with Coloring Techniques
- Move Around Quickly: Navigation Techniques
- Find a Packet Based on Various Characteristics
- Build Permanent Coloring Rules
- Identify a Coloring Source
- Use the Intelligent Scrollbar with Custom Coloring Rules
- Apply Temporary Coloring
- Mark Packets of Interest
Spot Network and Application Issues with Time Values and Summaries
- Examine the Delta Time (End-of-Packet to End-of-Packet)
- Set a Time Reference
- Compare Timestamp Values
- Compare Timestamps of Filtered Traffic
- Enable and Use TCP Conversation Timestamps
- Compare TCP Conversation Timestamp Values
- Determine the Initial Round Trip Time (iRTT)
- Troubleshooting Example Using Time
- Analyze Delay Types
Create and Interpret Basic Trace File Statistics
- Examine Trace File Summary Information
- View Active Protocols
- Graph Throughput to Spot Performance Problems Quickly
- Locate the Most Active Conversations and Endpoints
- Other Conversation Options
- Graph the Traffic Flows for a More Complete View
- Burst Statistics
- Numerous Other Statistics are Available
- Quick Overview of VoIP Traffic Analysis
- SIP and RTP Analysis Overview
- SIP Call Setup
- Analyzing Call Setup with SIP
- Session Bandwidth and RTP Port Definition
Focus on Traffic Using Display Filters
- Display Filters
- Filter on Conversations/Endpoints
- Build Filters Based on Packets
- Display Filter Syntax
- Use Comparison Operators and Advanced Filters
- Filter on Text Strings
- Build Filters Based on Expressions
- Watch for Common Display Filter Mistakes
- Share Your Display Filters
TCP/IP Communications and Resolutions Overview
- TCP/IP Functionality
- When Everything Goes Right
- The Multi-Step Resolution Process
- Resolution Helped Build the Packet
- Where Faults Can Occur
- Typical Causes of Slow Performance
Analyze DNS Traffic
- DNS Overview
- DNS Packet Structure
- DNS Queries
- Filter on DNS Traffic
- Analyze Normal/Problem DNS Traffic
Analyze ARP Traffic
- ARP Overview
- ARP Packet Structure
- Filter on ARP Traffic
- Analyze Normal/Problem ARP Traffic
Analyze IPv4 Traffic
- IPv4 Overview
- IPv4 Packet Structure
- Analyze Broadcast/Multicast Traffic
- Filter on IPv4 Traffic
- IP Protocol Preferences
- Analyze Normal/Problem IP Traffic
Analyze ICMP Traffic
- ICMP Overview
- ICMP Packet Structure
- Filter on ICMP Traffic
- Analyze Normal/Problem ICMP Traffic
Analyze UDP Traffic
- UDP Overview
- Watch for Service Refusals
- UDP Packet Structure
- Filter on UDP Traffic
- Follow UDP Streams to Reassemble Data
- Analyze Normal/Problem UDP Traffic
Analyze TCP Protocol
- TCP Overview
- The TCP Connection Process
- TCP Handshake Problem
- Watch Service Refusals
- TCP Packet Structure
- The TCP Sequencing/Acknowledgment Process
- Packet Loss Detection in Wireshark
- Fast Recovery/Fast Retransmission Detection in Wireshark
- Retransmission Detection in Wireshark
- Out-of-Order Segment Detection in Wireshark
- Selective Acknowledgement (SACK)
- Window Scaling
- Window Size Issue: Receive Buffer Problem
- Window Size Issue: Unequal Window Size Beliefs
- TCP Sliding Window Overview
- Troubleshoot TCP Quickly with Expert Info
- Filter on TCP Traffic and TCP Problems
- Properly Set TCP Preferences
- Follow TCP Streams to Reassemble Data 16. Examine Advanced Trace File Statistics
- Build Advanced IO Graphs
- Graph Round Trip Times
- Graph TCP Throughput
- Find Problems Using TCP Time-Sequence Graphs
Graph Traffic Characteristics
- Advanced I/O Graphing
- Graph Round Trip Times
- Graph TCP Throughput
- Find Problems Using TCP Time Sequence Graphs
Analyze HTTP Traffic
- HTTP Overview
- HTTP Packet Structure
- Filter on HTTP Traffic
- Reassembling HTTP Objects
- HTTP Statistics
- HTTP Response Time
- Overview of HTTP/2
- HTTP/2 Analysis Fundamentals
- HTTP /2 Frame Format
- Analyze Normal/Problem HTTP Traffic
Analyze TLS-Encrypted Traffic (HTTPS)
- Analyze HTTPS Traffic
- Encrypted Alerts
- Decryption Steps
- Filter on SSL
Review Your 10 Key Troubleshooting Steps
- Baseline "Normal Traffic
- Use Color
- Look Who's Talking: Examine Conversations and Endpoints
- Focus by Filtering
- Create Basic IO Graphs
- Examine Delta Time Values
- Examine the Expert System
- Follow the Streams
- Graph Bandwidth Use, Round Trip Time, and TCP Time/Sequence Information
- Watch Refusals and Redirections