Open Tutorial: Packet Analysis (0.5 days)
Synopsis
The tutorial is a snapshot of some of the labs that are delivered in the 3 or 5 day Network security workshops that are delivered by APNIC. The focus of the tutorial is to introduce packet analysis concepts by explaining various protocols, tools and strategies to analyse packets to enhance security and help with troubleshooting. This tutorial aims at providing attendees a practical approach to:
- Overview of protocols.
- Packet Analysis using tcpdump and other tools.
- Strategies for packet analysis including encrypted traffic.
Target audience
- Engineers, Network Managers and Operators, and Security policy makers who are interested in network security and want to gain an understanding of how to analyse traffic for security and troubleshooting.
Prerequisites
It is assumed that participants have a basic understanding of
- Network operations, Internet technologies, OSI reference model and TCP/IP.
- Basic Linux command line (CLI) skills.
We recommend the following Academy courses be completed before the start of the tutorial:
- Network security fundamentals: https://academy.apnic.net/en/webinar-courses/network-security-fundamentals/
- Introduction to Cybersecurity: https://academy.apnic.net/en/course/introduction-to-cybersecurity/
- Linux Basics virtual lab: https://academy.apnic.net/en/virtual-labs/
Course outline
- Overview of protocols
- Introduction to packet capturing
- Overview of various tools. For example tcpdump, tcpreplay, cloudshark, tshark and wireshark
- Strategies for packet analysis
- Utilising metadata to analyse encrypted traffic
Other requirements
- Online – Participants are advised to bring their own laptop or desktop computers with high-speed internet access and administrative access to system. It is also recommended that computers have Intel i5 or i7 processor, >=8GB of RAM and 30GB of free hard disk space.
- Face to face – Participants are advised to bring their own laptop computers with high-speed Wi-Fi (802.11a/g/n/ac) and administrative access to system. It is also recommended that laptops have Intel i5 or i7 processor, >=8GB of RAM and 30GB of free hard disk space.
- Software: SSH Client, Telnet Client, VirtualBox/VMware
- Confirm Secure SHell (SSH) is allowed from the office or home network to access the lab infrastructure? Test ssh connectivity, try to connect to route-views.routeviews.org. For example from the CLI type: ssh [email protected]
- Attendees must have an APNIC Academy login account. If you don’t have one already, you can create an account for free at https://academy.apnic.net/
- Please test the speed of your Internet connection to the servers where the Virtual Machines (VMs) are hosted at the Learn on Demand data centres, using the speed test tool at https://www.learnondemandsystems.com/speedtest/