Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Download the network_traffic.pcapng file, which was captured on one Kali box in the class infrastructure. Based on the network knowledge that you learned from this

image text in transcribed

Download the network_traffic.pcapng file, which was captured on one Kali box in the class infrastructure. Based on the network knowledge that you learned from this class so far, analyze the network traffic using Wireshark, and write a one-page report. From the packet capture, what activities can you infer about the users on the class network when the packets were captured? Please explain your answers with evidence you gather from the pcap file. Don't include screen shots. If you need to refer to packets, use the packet number you can observe from Wireshark. Please note that you will see many RDP related traffic which is not interesting, and you do not need to report anything regarding this traffic eth.addr == 00:11:11:00:11:15 ip.addr == 192.168.0.5 !(ip.addr == 192.168.0.5) tcp udp iCmp arp !(tcp.port == 53) tcp.port == 80 || udp.port == 80 http not arp and not (udp.port == 53) not (tcp.port == 80) and not (tcp.port == 25) and ip.addr == 192.168.0.5 Download the network_traffic.pcapng file, which was captured on one Kali box in the class infrastructure. Based on the network knowledge that you learned from this class so far, analyze the network traffic using Wireshark, and write a one-page report. From the packet capture, what activities can you infer about the users on the class network when the packets were captured? Please explain your answers with evidence you gather from the pcap file. Don't include screen shots. If you need to refer to packets, use the packet number you can observe from Wireshark. Please note that you will see many RDP related traffic which is not interesting, and you do not need to report anything regarding this traffic eth.addr == 00:11:11:00:11:15 ip.addr == 192.168.0.5 !(ip.addr == 192.168.0.5) tcp udp iCmp arp !(tcp.port == 53) tcp.port == 80 || udp.port == 80 http not arp and not (udp.port == 53) not (tcp.port == 80) and not (tcp.port == 25) and ip.addr == 192.168.0.5

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Database Concepts

Authors: David M Kroenke, David J Auer

6th Edition

0132742926, 978-0132742924

More Books

Students also viewed these Databases questions

Question

How many Tables Will Base HCMSs typically have? Why?

Answered: 1 week ago

Question

What is the process of normalization?

Answered: 1 week ago