In the OIDA methodology (Observe, Identify, Dissect, Analyze), the Identify phase is crucial for pinpointing relevant data within captured network traffic. This article focuses on effectively using Wireshark and Profitap's IOTA for this critical step.
This article is part of a series. Each article covers one of the four phases of OIDA: Observe, Identify, Dissect, Analyze.
Wireshark offers several powerful tools for identifying important traffic patterns and conversations.
The Conversations dialog is a key tool for identifying communication patterns between network endpoints.
Combining the Conversations dialog with display filters allows for precise traffic isolation:
This technique allows for progressive refinement of your view, helping to zero in on relevant traffic.
The Endpoints dialog summarizes all endpoints in the capture:
The Protocol Hierarchy window offers a breakdown of protocols present in the capture:
Use the Protocol Hierarchy to:
Profitap's IOTA offers real-time dashboards that quickly highlight areas of interest in network traffic. The ability to switch between dashboards and filter on data allows you to quickly pivot from bird's eye view to packet-level detail.
The Application Overview dashboard provides an immediate overview of application usage on the network.
Key features:
To use effectively:
The TCP Analysis dashboard in IOTA is comparable to Wireshark's Conversations dialog, but offers real-time insights.
How to use:
The TCP Analysis dashboard allows for quick identification of unusual traffic patterns or potential bottlenecks in real-time.
Mastering the identification phase in packet analysis involves effectively using tools like Wireshark's Conversations dialog, Endpoints dialog, and Protocol Hierarchy, as well as IOTA's Application and Flow dashboards. By leveraging these tools, analysts can quickly pinpoint relevant data, identify unusual patterns, and focus their investigation on the most pertinent information.
To ensure a thorough approach to the Identify phase, consider the following checklist:
By following this checklist and effectively using the tools discussed, analysts can ensure a comprehensive approach to the Identify phase, setting a solid foundation for the subsequent stages of packet analysis.
This article is part of a series. Each article covers one of the four phases of OIDA: Observe, Identify, Dissect, Analyze.