<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.frotmail.nl/index.php?action=history&amp;feed=atom&amp;title=Network_Analysis</id>
	<title>Network Analysis - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.frotmail.nl/index.php?action=history&amp;feed=atom&amp;title=Network_Analysis"/>
	<link rel="alternate" type="text/html" href="https://wiki.frotmail.nl/index.php?title=Network_Analysis&amp;action=history"/>
	<updated>2026-06-15T08:00:29Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.3</generator>
	<entry>
		<id>https://wiki.frotmail.nl/index.php?title=Network_Analysis&amp;diff=93&amp;oldid=prev</id>
		<title>Eric: Created page with &quot;=Netwerk analyse= ==tcpdump== Met TCPdump maken we een dump van het verkeer naar disk:  tcpdump -w filename.pcap  ==tcpdstat== http://frotmail.nl/tools/tcpdstat-uw.tar.gz mirror http://staff.washington.edu/dittrich/talks/core02/tools/tools.html Original site Deze tool stelt ons in staat om statistieken van de pcap file uit te lezen:  root@testd00s:/home/eric# tcpdstat test.pcap    DumpFile:  test.pcap  FileSize: 441.91MB  pcap_dispatch:truncated dump file; tried...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.frotmail.nl/index.php?title=Network_Analysis&amp;diff=93&amp;oldid=prev"/>
		<updated>2022-04-05T09:36:29Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;=Netwerk analyse= ==tcpdump== Met TCPdump maken we een dump van het verkeer naar disk:  tcpdump -w filename.pcap  ==tcpdstat== &lt;a href=&quot;/index.php?title=Http://frotmail.nl/tools/tcpdstat-uw.tar.gz_mirror&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;Http://frotmail.nl/tools/tcpdstat-uw.tar.gz mirror (page does not exist)&quot;&gt;http://frotmail.nl/tools/tcpdstat-uw.tar.gz mirror&lt;/a&gt; &lt;a href=&quot;/index.php?title=Http://staff.washington.edu/dittrich/talks/core02/tools/tools.html_Original_site&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;Http://staff.washington.edu/dittrich/talks/core02/tools/tools.html Original site (page does not exist)&quot;&gt;http://staff.washington.edu/dittrich/talks/core02/tools/tools.html Original site&lt;/a&gt; Deze tool stelt ons in staat om statistieken van de pcap file uit te lezen:  root@testd00s:/home/eric# tcpdstat test.pcap    DumpFile:  test.pcap  FileSize: 441.91MB  pcap_dispatch:truncated dump file; tried...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=Netwerk analyse=&lt;br /&gt;
==tcpdump==&lt;br /&gt;
Met TCPdump maken we een dump van het verkeer naar disk:&lt;br /&gt;
 tcpdump -w filename.pcap&lt;br /&gt;
&lt;br /&gt;
==tcpdstat==&lt;br /&gt;
[[http://frotmail.nl/tools/tcpdstat-uw.tar.gz mirror]] [[http://staff.washington.edu/dittrich/talks/core02/tools/tools.html Original site]]&lt;br /&gt;
Deze tool stelt ons in staat om statistieken van de pcap file uit te lezen:&lt;br /&gt;
 root@testd00s:/home/eric# tcpdstat test.pcap&lt;br /&gt;
 &lt;br /&gt;
 DumpFile:  test.pcap&lt;br /&gt;
 FileSize: 441.91MB&lt;br /&gt;
 pcap_dispatch:truncated dump file; tried to read 142 captured bytes, only got 8&lt;br /&gt;
 Id: 201109020808&lt;br /&gt;
 StartTime: Fri Sep  2 08:08:01 2011&lt;br /&gt;
 EndTime:   Fri Sep  2 09:14:24 2011&lt;br /&gt;
 TotalTime: 3983.05 seconds&lt;br /&gt;
 TotalCapSize: 435.54MB  CapLen: 49298 bytes&lt;br /&gt;
 # of packets: 417725 (435.54MB)&lt;br /&gt;
 AvgRate: 918.42Kbps  stddev:7963.55K   PeakRate: 98.10Mbps &lt;br /&gt;
 &lt;br /&gt;
 ### IP flow (unique src/dst pair) Information ###&lt;br /&gt;
 # of flows: 282  (avg. 1481.29 pkts/flow)&lt;br /&gt;
 Top 10 big flow size (bytes/total in %):&lt;br /&gt;
  68.8% 22.1%  3.9%  0.7%  0.5%  0.4%  0.3%  0.3%  0.1%  0.1% &lt;br /&gt;
 &lt;br /&gt;
 ### IP address Information ###&lt;br /&gt;
 # of IPv4 addresses: 147 &lt;br /&gt;
 Top 10 bandwidth usage (bytes/total in %):&lt;br /&gt;
  99.9% 91.1%  4.0%  0.9%  0.5%  0.5%  0.3%  0.2%  0.1%  0.1%&lt;br /&gt;
 ### Packet Size Distribution (including MAC headers) ###&lt;br /&gt;
 &amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;br /&gt;
  [   32-   63]:       3811&lt;br /&gt;
  [   64-  127]:     161765&lt;br /&gt;
  [  128-  255]:      13197&lt;br /&gt;
  [  256-  511]:       1445&lt;br /&gt;
  [  512- 1023]:       2039&lt;br /&gt;
  [ 1024- 2047]:     227130&lt;br /&gt;
  [ 2048- 4095]:       1818&lt;br /&gt;
  [ 4096- 8191]:       1034&lt;br /&gt;
  [ 8192-16383]:       3393&lt;br /&gt;
  [16384-32767]:       2058&lt;br /&gt;
  [32768-65535]:         35&lt;br /&gt;
 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br /&gt;
  &lt;br /&gt;
 &lt;br /&gt;
 ### Protocol Breakdown ###&lt;br /&gt;
 &amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;br /&gt;
      protocol		packets			bytes		bytes/pkt&lt;br /&gt;
 ------------------------------------------------------------------------&lt;br /&gt;
 [0] total           417725 (100.00%)        456692736 (100.00%)   1093.29&lt;br /&gt;
 [1] ip              408445 ( 97.78%)        455856868 ( 99.82%)   1116.08&lt;br /&gt;
 [2]  tcp            390934 ( 93.59%)        451225115 ( 98.80%)   1154.22&lt;br /&gt;
 [3]   ssh              104 (  0.02%)           193406 (  0.04%)   1859.67&lt;br /&gt;
 [3]   http(s)       261759 ( 62.66%)        346302456 ( 75.83%)   1322.98&lt;br /&gt;
 [3]   http(c)       125881 ( 30.13%)        103320254 ( 22.62%)    820.78&lt;br /&gt;
 [3]   https           3190 (  0.76%)          1408999 (  0.31%)    441.69&lt;br /&gt;
 [2]  udp             17445 (  4.18%)          4627793 (  1.01%)    265.28&lt;br /&gt;
 [3]   dns               32 (  0.01%)             3119 (  0.00%)     97.47&lt;br /&gt;
 [3]   netb-ns         2815 (  0.67%)           260114 (  0.06%)     92.40&lt;br /&gt;
 [3]   netb-se           74 (  0.02%)            17555 (  0.00%)    237.23&lt;br /&gt;
 [3]   mcast            492 (  0.12%)            61621 (  0.01%)    125.25&lt;br /&gt;
 [3]   other          14032 (  3.36%)          4285384 (  0.94%)    305.40&lt;br /&gt;
 [2]  igmp               66 (  0.02%)             3960 (  0.00%)     60.00&lt;br /&gt;
 &amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;br /&gt;
==EtherApe==&lt;br /&gt;
Deze tool kan grafisch weergeven waar verbindingen naartoe lopen en hoeveel data deze verwerken.&lt;/div&gt;</summary>
		<author><name>Eric</name></author>
	</entry>
</feed>