Urgent.News

What's breaking now, across thousands of outlets.

Tech

Network Forensics: Understanding TCP/IP Protocols (Week 3)

This week, we are focusing into the analysis of TCP/IP protocols, focusing on how to examine network flows, extract data, and analyze higher-layer traffic. What is Flow Analysis? Flow analysis is the "examination of sequences of related packets ('flows')". This process is typically conducted to identify traffic patterns, isolate suspicious activity, analyze higher-layer protocols, or extract…

This week's focus is on the analysis of TCP/IP protocols, specifically examining network flows, extracting data, and analyzing higher-layer traffic. Flow analysis involves examining sequences of related packets, often to identify traffic patterns, isolate suspicious activity, analyze higher-layer protocols, or extract data. Key tools for flow analysis include Wireshark, Tshark, Tcpflow, Pcapcat, and Tcpxtract.

Techniques include listing conversations and flows, exporting flows, file and data carving, and higher-layer traffic analysis. Understanding higher-layer protocols such as HTTP and SMTP is crucial for contextualizing network activity.

Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Why Your Payment Got Charged Twice: Idempotency Keys Explained

Maya taps Pay for a $20 ride. Ten seconds later: request timed out. The app retries, and Maya gets charged $40 . The retry went through. So did the first attempt.

  • Idempotent operations can be repeated without changing outcome beyond initial application
  • Idempotency keys are unique strings included in payment requests to prevent duplication
  • Server stores response to idempotency key; same key triggers returning saved response

More from Tuesday 6 October →