This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

anomaly detection

0

Can wireshark be use to detect anomaly in capured packets?

asked 14 Jul '14, 14:18

Maigana's gravatar image

Maigana
11668
accept rate: 0%

The question sounds suspiciously like a homework or test question.

If so, my inclination would be to say learn a bit about the capabilities of Wireshark (and/or communications protocol analyzers, in general). :)

There's lots of information available on the web.

(14 Jul '14, 14:40) Bill Meier ♦♦

2 Answers:

0

Yes, but you have to decide what constitutes an anomaly, and if it's not one of the conditions that Wireshark already highlights (via a coloring rule or an Expert Info message), then you'll have to create a coloring rule or display filter to identify the anomalous packets.

answered 14 Jul '14, 14:36

Jim%20Aragon's gravatar image

Jim Aragon
7.2k733118
accept rate: 24%

0

see my answer to a very similar question:

http://ask.wireshark.org/questions/31235/wireshark-question

BTW: There is no standardized network, so everything we would say about an 'anomaly' in captured packets, could be totally normal for anybody else.

If you are looking for an 'expert system' that tells you that it found some 'standard' problems in your capture file, you could use the Expert info messages, as mentioned by @Jim Aragon. But don't expect too much from that. It's just an overview of some typical problems, that helps knowledgeable troubleshooters to nail down a problem.

I won't be like this: Your application Expencemaster used by user Marky Mark on the server-farm sf2763 in the datacenter DC272 is slow in response between 09:00 AM and 11:00 AM, because there is an overload of the DNS servers at that time.

That won't happen, at least not in the next couple of years.

Regards
Kurt

answered 15 Jul '14, 02:16

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%