Reference no: EM134026770
Assignment: Lab Exercise: Analyze Network Traffic using Wireshark
In this lab, please useuse Wireshark, a popular open-source network traffic capture and analysis tool. You will analyze the provided Wireshark capture file, looking at various data packets of IP, TCP, DNS and HTTP protocol, finding request packets, locating and analyzing responses, looking at traffic statistics, and answering questions. You will be provided with a lab guide, describing detailed steps to be taken.
Instructions
Step I: Preparation
i. Spin up your Virtual Machine, this can be found on the lefthand nav bar "MARS: Virtual Learning Environment" --> Virtual Lab Access
ii. Locate Wireshark on your VM
iii. Read Chapter 3 of Wireshark User Guide (User Interface), this can be found inside the "Lab Resources Unit 2" folder on your VMs desktop
iv. Download the provided capture file: Unit 2 Wireshark Capture File
v. Download and review the lab guide "CLCS635 Unit 2 Analyzing Network Traffic Using Wireshark.docx".
Step II: Open and Explore the Capture File
i. Launch Wireshark and open the provided capture file.
ii. Familiarize yourself with the Wireshark interface:
o Packet list pane (top)
o Packet details pane (middle)
o Packet bytes pane (bottom)
iii. Take a screenshot of the Wireshark interface showing the opened capture file.
Step III: Analyze IP Protocol Packets
i. Apply a display filter to show only IP packets.
ii. Examine the source and destination IP addresses in several packets.
iii. Identify the IP version (IPv4 or IPv6) used in the capture.
iv. Take a screenshot showing IP packet details.
Step IV: Analyze TCP Protocol Packets
i. Apply a display filter to show only TCP packets.
ii. Identify TCP handshake packets (SYN, SYN-ACK, ACK).
iii. Examine port numbers used in the communication.
iv. Take a screenshot showing TCP handshake packets.
Step V: Analyze DNS Protocol Packets
i. Apply a display filter to show only DNS packets.
ii. Identify DNS query packets and their corresponding response packets.
iii. Extract domain names being queried.
iv. Take a screenshot showing DNS query and response packets.
Step VI: Analyze HTTP Protocol Packets
i. Apply a display filter to show only HTTP packets.
ii. Identify HTTP GET/POST requests and their corresponding responses.
iii. Examine HTTP headers and status codes.
iv. Take a screenshot showing HTTP request and response packets.
Step VII: Generate and Analyze Traffic Statistics
Use Wireshark's statistics tools to generate:
i. Protocol hierarchy statistics
ii. Conversations statistics
iii. Endpoints statistics
iv. Take screenshots of each statistics view.
Step VIII: Answer Analysis Questions
Answer the following questions based on your analysis:
i. What is the most common protocol observed in the capture file? Get the instant assignment help.
ii. Identify three different IP addresses involved in the communication and their roles.
iii. What types of DNS queries are present in the capture?
iv. Describe the HTTP transactions observed, including requested resources and response codes.
v. What can you determine about the network topology from the capture?