Practical Packet Analysis, 3rd Edition

Practical Packet Analysis, 3rd Edition
Using Wireshark to Solve Real-World Network Problems
Chris Sanders
March 2017, 368 pp.

|| PDF file available now! EPUB and MOBI coming soon. Print books will ship in April. ||

Wireshark is the world’s most popular network sniffer that makes capturing packets easy, but it won’t be much help if you don’t have a solid foundation in packet analysis.

Practical Packet Analysis, 3rd Edition will show you how to make sense of your PCAP data and let you start troubleshooting the problems on your network. This third edition is updated for Wireshark 2.0.5 and IPv6, making it the definitive guide to packet analysis and a must for any network technician, administrator, or engineer. This updated version includes two new chapters that will teach you how to use the powerful command-line packet analyzers tcpdump and TShark as well as how to read and reference packet values using a packet map.

Practical Packet Analysis will introduce you to the basics of packet analysis, starting with how networks work and how packets travel along the wire. Then you’ll move on to navigating packets and using Wireshark for packet capture and analysis. The book then covers common lower-layer and upper-layer protocols and provides you with solutions to real-world scenarios like Internet connectivity issues, how to intercept malware traffic, and fighting a slow network.

You’ll learn how to:

  • Monitor your network in real-time and tap live network communications
  • Recognize common network protocols including TCP, IPv4 and IPv6, SMTP, and ARP
  • Build customized capture and display filters to quickly navigate through large numbers of packets
  • Troubleshoot and resolve common network problems like loss of connectivity, DNS issues, and sluggish speeds with packet analysis
  • Understand how modern exploits and malware behave at the packet level
  • Carve out data in a packet to retrieve the actual files sent across the network
  • Graph traffic patterns to visualize the data flowing across your network
  • Use advanced Wireshark features to understand confusing captures
  • Build statistics and reports to help you better explain technical network information to non-techies

Whether you’re a budding network analyst in need of a headfirst dive into packet analysis or an experienced administrator searching for new tricks, look no further than the third edition of Practical Packet Analysis.

Author Bio 

Chris Sanders is a computer security consultant, researcher, and educator. He is also the author of Applied Network Security Monitoring, and writes regularly for his blog, Sanders uses packet analysis daily to catch bad guys and find evil.

Table of contents 


Chapter 1: Packet Analysis and Network Basics
Chapter 2: Tapping into the Wire
Chapter 3: Introduction to Wireshark
Chapter 4: Working with Captured Packets
Chapter 5: Advanced Wireshark Features
Chapter 6: Packet Analysis on the Command Line
Chapter 7: Network Layer Protocols
Chapter 8: Transport Layer Protocols
Chapter 9: Common Upper-Layer Protocols
Chapter 10: Basic Real-World Scenarios
Chapter 11: Fighting a Slow Network
Chapter 12: Packet Analysis for Security
Chapter 13: Wireless Packet Analysis

Appendix A: Further Reading
Appendix B: Navigating Packets

View the detailed Table of Contents (PDF)
View the Index (PDF)


Read Chris Sanders’ blog post about the third edition release of Practical Packet Analysis!

Praise for Practical Packet Analysis:

“A wealth of information. Smart, yet very readable, and honestly made me excited to read about packet analysis.”
—Lauren Malhoit, TechRepublic

“I'd recommend this book to junior network analysts, software developers, and the newly minted CSE/CISSP/etc.—folks that just need to roll up their sleeves and get started troubleshooting network (and security) problems.”
—Gunter Ollmann, Chief Technical Officer of IOActive, Technical Info

“The next time I investigate a slow network, I'll turn to Practical Packet Analysis. That's perhaps the best praise I can offer on any technical book.”
Michael W. Lucas, author of Absolute FreeBSD and Network Flow Analysis

“An essential book if you are responsible for network administration on any level.”
—James Pyles, Linux Pro Magazine

“I recommend this book to folks that aren’t Wireshark experts. (Even those who have plenty of Wireshark experience may pick up a new trick or two.)”
—Jim Clausing, SANS Internet Storm Center Diary

"An excellent jump-start for novices."
—Jeremy Stretch,

“This book really scores in the step-by-step analysis of typical networking problems and how you need to interpret the captured packets.”
—Network Security Newsletter

“It makes a great addition for someone in the one-to-three year range of their career. Whether this career is security-centric, network administration, or simply as a hobbyist, Chris Sanders made great work of keeping things simple yet informative for his readers.”
—J. Oquendo, The Ethical Hacker Network

“Stands out as a book that's a very useful learning resource, and one that makes the learning process a lot of fun.”
—Peter N.M. Hansteen, author of The Book of PF

“Very informative. It does a great job of giving readers what they need to know to do packet analysis and then jumps right in with vivid real life examples of what to do with Wireshark.”
—Daniel Boland,

“Are there unknown hosts chatting away with each other? Is my machine talking to strangers? You need a packet sniffer to really find the answers to these questions. Wireshark is one of the best tools to do this job and this book is one of the best ways to learn about that tool.”
—Brian Turner, Free Software Magazine

“Perfect for the beginner to intermediate.”
—Daemon News

Extra Stuff 

Hashes for
MD5: 35E5CD0EC11A3F7E3951C468E447D040
SHA1: 232687A43B2E23E97338021D53697F6DEC2D0298
SHA256: 1F0130F1E2C335BEDDB317A0F2267D2347892D90A2F323C44B5EB10F7978B9C0)