A Beginner's Guide to Network Traffic Analysis with Wireshark

Wireshark is the undisputed king of network protocol analyzers. It allows you to see what's happening on your network at a microscopic level. For cybersecurity professionals, it's an indispensable tool for incident response, malware analysis, and network troubleshooting. If the network is the crime scene, Wireshark is the magnifying glass.

In this beginner's guide, we will explore the fundamental concepts of network traffic analysis, how to set up your first packet capture, and the essential filters you need to know.

Understanding the Basics: Packets and Protocols

Before diving into the tool, it's crucial to understand what you're actually looking at. Data sent over a network isn't sent as a single, continuous stream. It is broken down into smaller chunks called "packets."

Each packet contains two main components:

  1. The Payload: The actual data being transmitted (e.g., a piece of an image, an email, or a web page).
  2. The Headers: Metadata attached to the payload that tells the network where the packet came from, where it's going, and how to reassemble it. This relies heavily on the OSI model, encapsulating data with Ethernet, IP, and TCP/UDP headers.

Wireshark captures these packets as they cross your network interface card (NIC) and translates the raw binary data into human-readable formats.

Getting Started: Your First Capture

When you launch Wireshark, you are greeted with a list of available network interfaces (e.g., Wi-Fi, Ethernet, loopback). Selecting an interface and clicking the blue "shark fin" icon begins the capture.

By default, Wireshark captures traffic in promiscuous mode. Normally, your NIC only processes packets specifically addressed to its MAC address. Promiscuous mode tells the NIC to process every single packet it sees on the wire, regardless of the destination.

Once the capture is running, you'll see the main interface divided into three panes:

  • The Packet List: A chronological log of every captured packet.
  • The Packet Details: A hierarchical breakdown of the selected packet's headers and protocols.
  • The Packet Bytes: The raw hex and ASCII dump of the packet.

Mastering Wireshark Filters

A busy network can generate thousands of packets per second. Finding malicious activity in a haystack of normal traffic is impossible without filters. Wireshark uses two distinct types of filters:

Capture Filters

Capture filters limit the traffic that Wireshark records to the disk. They use the Berkeley Packet Filter (BPF) syntax and are applied before the capture begins. This is highly recommended for high-volume networks to prevent your hard drive from filling up.

  • Example: tcp port 443 (Captures only HTTPS traffic)
  • Example: host 192.168.1.50 (Captures only traffic to/from this specific IP)

Display Filters

Display filters are applied to traffic that has already been captured. They are incredibly powerful and use Wireshark's custom syntax.

  • ip.addr == 10.0.0.5: Shows traffic where the source or destination IP matches.
  • tcp.port == 80: Shows only unencrypted HTTP traffic.
  • http.request.method == "POST": Filters for HTTP POST requests, often useful for finding data exfiltration or login submissions.
  • dns: Displays only Domain Name System queries and responses.

Following the Stream

One of Wireshark's most powerful features for analysts is "Follow TCP Stream." Because data is broken into many packets, analyzing them individually can be tedious. If you find an interesting HTTP request, you can right-click the packet and select Follow -> TCP Stream.

Wireshark will automatically filter out all other traffic and reassemble the entire conversation between the client and the server in a new window. This makes reading unencrypted protocols (like HTTP, FTP, or Telnet) as easy as reading a text document.

Conclusion

Network traffic analysis is a deep and complex field, but Wireshark makes it accessible. By understanding how packets flow and learning how to filter out the noise, you can begin to spot anomalies, detect malware beacons, and understand the precise mechanics of a cyber attack.

In our next post, we will look at enterprise networking architecture and answer a common question: "VPNs vs. SD-WAN: Which is Better for Enterprise Security?"