Book Image

Network Analysis using Wireshark 2 Cookbook - Second Edition

By : Nagendra Kumar Nainar, Yoram Orzach, Yogesh Ramdoss
Book Image

Network Analysis using Wireshark 2 Cookbook - Second Edition

By: Nagendra Kumar Nainar, Yoram Orzach, Yogesh Ramdoss

Overview of this book

This book contains practical recipes on troubleshooting a data communications network. This second version of the book focuses on Wireshark 2, which has already gained a lot of traction due to the enhanced features that it offers to users. The book expands on some of the subjects explored in the first version, including TCP performance, network security, Wireless LAN, and how to use Wireshark for cloud and virtual system monitoring. You will learn how to analyze end-to-end IPv4 and IPv6 connectivity failures for Unicast and Multicast traffic using Wireshark. It also includes Wireshark capture files so that you can practice what you’ve learned in the book. You will understand the normal operation of E-mail protocols and learn how to use Wireshark for basic analysis and troubleshooting. Using Wireshark, you will be able to resolve and troubleshoot common applications that are used in an enterprise network, like NetBIOS and SMB protocols. Finally, you will also be able to measure network parameters, check for network problems caused by them, and solve them effectively. By the end of this book, you’ll know how to analyze traffic, find patterns of various offending traffic, and secure your network from them.
Table of Contents (20 chapters)

Understanding the NetBIOS protocol

Network Basic Input/Output System (NetBIOS) is a set of protocols developed in the early 1980s for LAN communications, in order to provide services for the session layer (fifth layer in the OSI model). A few years later, it was adopted by Microsoft for their networking over LAN, and then it was migrated for working over TCP/IP (NetBIOS over TCP/IP—NBT), which is discussed in RFC 1001 and 1002.

In today's networks, NetBIOS provides three services:

  • Name service (port 137) for name registration and name to IP address resolution. Also referred to as NetBIOS-NS.
  • Datagram distribution service (port 138) for service announcements by clients and servers. Also referred to as NetBIOS-DGM.
  • Session service (port 139) for session negotiation between hosts. This is used for accessing files, opening directories, and so on. Also referred to as NetBIOS...