Lab W5L5 (1)

.docx

School

University of Ottawa *

*We aren’t endorsed by this school

Course

8802

Subject

Electrical Engineering

Date

Apr 3, 2024

Type

docx

Pages

7

Uploaded by mabou055

Report
Week 5 Lab 5 – Apply Filters During Capturing Packets DUE: Week5 VALUE : 3%  Objective of this Assignment: In this lab, learners learn how to use and apply filters during Packet capture process to reduce to have precise data. Relevant Course Learning Requirements: CLR 4: Perform network analysis on various network packet captures to determine whether a security issue is present and an Indicator of Compromise (IoC) needs to be created. Lab Topology/Addressing
Week 5 Lab 5 – Apply Filters During Capturing Packets Lab summary: Apply Filters to reduce numbers of captured packet Background / Scenario Using packet capture tools and applications, generate lots of output and it will be hard to select specific packets for monitoring or investigation any ongoing attack. Using Filters, will reduce number of captured packet and it will sniff more specific packets, based on filtering criteria. Please note: 1) Screen shots provided in the Lab activities may not be the same as you see on the machine that you run Packet Capture tool. 2) “ Username” is your College username. 3) Save all screen captures and answers in a file named “W5_L5_ username .docx” and upload to the Week 5 Lab submission folder. Part 1) Filtering on Wireshark Run “Wireshark ” on PC1 Part 1) Capture Filter a) Select the profile that you have created under your username in Week2 Lab2. Click on the Bookmark icon ( ) on the Filter Toolbar. Add a new filter to the list of existing filters and take a screen capture. (By selecting Manage Capture Filters, then click on +)
Week 5 Lab 5 – Apply Filters During Capturing Packets In the “Filter Expression” add “host 10.10.4.21 and !(port 80)” Which packets are filtered by this filter?________________ b) Enter following as filter in the Filter toolbar and start capturing packet !(host 10.10.4.21) Stop capturing packets after 5 minutes and take a screen capture. c) Click on “Capture Option” in the main toolbar. Verify the same filter is shown in the Capture Filter columns for that specific interface also it shows in the Capture Filter Toolbar and take a screen capture. d) Clear the Filter by click on the “x” icon at the right side of filter toolbar. e) Click on the “Start” to start capturing packets. Make sure there is no longer any Filter applied. Part 2) Display Filters
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help