February 01, 2021

Crossing the 10 Million Mark: DDoS Attacks in 2020 ( Richard Hummel, Carol Hildebrandon)

Crossing the 10 Million Mark: DDoS Attacks in 2020 ( Richard Hummel, Carol Hildebrandon)

DDoS Attacks in 2020

Not all world records are cause for celebration—just look at the DDoS attack numbers from 2020. For the first time in history, we observed more than 10 million DDoS attacks in a single year, with NETSCOUT’s ATLAS Security Engineering and Response Team (ASERT) observing 10,089,687 attacks over the course of the year. That’s nearly 1.6 million more attacks than 2019’s count of 8.5 million.

January 25, 2021

A Quick Note About TCP Sequence Numbers

A Quick Note About TCP Sequence Numbers
I’ve received a lot of feedback from my readers expressing their gratitude that my articles/videos are short and to the point. 

To those people who took the time to send their feedback, thank you.

In this video, I briefly discuss TCP sequence numbers and acknowledgements, recognizing that this topic can often be very overwhelming. I keep the explanation quick and simple, focusing on a stream of traffic flowing from a server on port 443 to a client. Make sure you have Wireshark installed and follow along.

January 15, 2021

Our Curious Habits (Paul Smith)

 

Our Curious Habits (Paul Smith)

As an engineer, I’m often accused by my non-engineer brethren of being overly analytical. I confess that I can’t help scrutinizing some things (well...most things) to try and figure out how they work. This can lead to satisfaction and a boost in self-assurance when things work as expected, and a compulsive drive for further analysis when they don’t. I have been blessed (cursed?) with this inclination for as long as I can remember. I have been formally trained for it in school and throughout my career. Reinforced by a lifetime of use, this habit is unlikely to ever change.

January 06, 2021

Wireshark Display Filter Tip: Show Specific Frame Numbers

 

Try this Wireshark display filter
Wireshark’s features can really be a catch 22. In one way, they are very powerful but on another hand, many of them are difficult to find. Every so often I find a gem of a tip or trick which makes packet analysis a lot easier.

In this video I share a different kind of display filter that you may not be familiar with. I’m sure you have used MAC, IP address, TCP, UDP and maybe even some application layer display filters. I find that sometimes I need to display just a few packets that might not have MAC, IP, TCP or UDP port numbers in common.

As you will see in the video, one way to address this challenge is to simply Mark the packets and then apply a display filter for just marked packets. The other way is to use the following display filter syntax frame.number in {frame numbers} this will simply display any frame number you provide in the curly braces.

By focusing on a lesser‑known display filter, I demonstrate how to cut through noisy captures and quickly zero in on the traffic you actually need to inspect.

December 15, 2020

Wireshark Tutorial - Find TCP Delays (Chris Greer)

Wireshark Tutorial - Find TCP Delays (Chris Greer)
Chris Greer’s Wireshark Tutorial: Fixing Slow Applications is a sharp, practical walkthrough that shows you how to pinpoint performance bottlenecks within your  trace files. The video focuses on a clever filtering technique Greer uses to quickly isolate slow connections—an approach that saves time, cuts through noise, and helps you zero in on the real pain points. If you’ve ever stared at a huge capture file wondering where to begin, this tutorial gives you a clear, confident starting point.   

Popular post in the past 30 days