_CH05_MakrisJohn
docx
keyboard_arrow_up
School
University of Cincinnati, Main Campus *
*We aren’t endorsed by this school
Course
3075C
Subject
Information Systems
Date
Feb 20, 2024
Type
docx
Pages
5
Uploaded by DoctorFlagCamel35
IT3075C-002: Network Monitoring & IPS
Student Name
Assignment 05:
Full Packet Capture Data
1.
Wireshark screenshot
Figure 1. Wireshark screenshot
Wireshark allows you to save the packets you capture as multiple file types. What is Wireshark's native file format extension? The Native file format for Wireshark is PCAP, short for Packet Capture. Wireshark uses this file format to store captures of network traffic and information about these packets. PCAP is a platform-independent that means
it can be captured on one system and analyzed on another. When capturing packets, you can apply filters to limit the types of traffic being captured.
IT3075C-002: Network Monitoring & IPS
Student Name
Assignment 05:
Full Packet Capture Data
2.
Dumpcap screenshot
Figure 2. Dumpcap screenshot
The book uses an example that captures packets on the interface eth1. What
interface did you use?
The command used would be the ens160.
How did you determine the interface used?
By following along from the textbook while changing to the dumpcap terminal but changed according to my interface list.
Without specifying otherwise, what file format will Dumpcap save the packet(s)?
Dumpcap saves the file format in pcapng
IT3075C-002: Network Monitoring & IPS
Student Name
Assignment 05:
Full Packet Capture Data
How can you specify the file format of the packet(s) be saved a PCAP?
By using -P can save the file as PCAP instead of PCAP-NG
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
- Access to all documents
- Unlimited textbook solutions
- 24/7 expert homework help
IT3075C-002: Network Monitoring & IPS
Student Name
Assignment 05:
Full Packet Capture Data
3.
Daemonlogger screenshot
Figure 3. Daemonlogger screenshot
What option can you use to specify the directory for the packet(s) to be saved?
Using -I which enables you to log data to a specified directory of your own choices.
IT3075C-002: Network Monitoring & IPS
Student Name
Assignment 05:
Full Packet Capture Data
4. Netsniff-NG screenshot
Figure 4. Netsniff-NG