Tshark によるプロトコル解析

Tshark を活用した高度なプロトコル解析手法を学びます。TCP/UDP ストリームの再構築、特定のプロトコルフィールドの抽出、そして脅威ハンティングやマルウェア検知に向けたトラフィック解析の自動化技術を習得しましょう。

Cybersecurity EngineerサイバーセキュリティWireshark

💡 このチュートリアルは英語版からAIによって翻訳されています。原文を確認するには、 ここをクリックしてください

はじめに

Tshark によるプロトコル解析では、packet capture を readable conversation と structured evidence に変える protocol-aware command-line workflow を学びます。3 個の guided lab で capture/display filter、TCP stream reconstruction、field extraction、CSV を扱い、最後の challenge で prepared PCAP から command-and-control activity を特定します。

isolated Ubuntu 22.04 VM で local traffic と準備済み capture を使用します。packet summary を手作業で追う代わりに、decoded HTTP/DNS field を query し、analysis artifact を保存し、shell や downstream system が利用できる output を作ります。

学習内容

  • Tshark で traffic を capture し、PCAP evidence を保存して collection と offline analysis を区別
  • protocol-aware display filter で HTTP、DNS、IP、request traffic を分離
  • protocol hierarchy statistics で capture の構成を評価
  • TCP stream index を特定し、完全な HTTP request-response conversation を再構築
  • reconstructed stream を text evidence として保存し、GET/POST activity を解釈
  • frame、IP、DNS、HTTP URI、host、User-Agent field を clean CSV-style output に抽出
  • DNS query を deduplicate し、suspicious domain と download URI を分離する threat-hunting workflow を自動化

このコースの対象者

packet の基礎を理解し、raw capture summary より豊かな protocol analysis を求める SOC 学習者、Security Analyst、network investigator、Linux user 向けです。tcpdump 入門の次に適しますが、同等経験でも受講できます。

前提知識: 基本的な Linux shell pipeline/redirection と、IP、TCP stream、DNS、HTTP、port、PCAP の知識。Tshark/Wireshark 経験は不要です。

学習環境: ブラウザー Ubuntu 22.04 VM で行う 4 個の独立 activity(3 guided lab、1 challenge)。Tshark、local DNS/HTTP traffic、sample capture、prepared suspicious PCAP が用意され、Wireshark desktop GUI は使いません。

よくある質問

tcpdump の packet analysis course と何が違いますか?

tcpdump course は interface capture、BPF、raw payload、PCAP を重視します。本 course は Tshark の Wireshark dissector/display filter で named field、TCP conversation、protocol statistics、structured export を扱います。

Wireshark graphical application は必要ですか?

不要です。すべて Tshark を terminal で使用します。Wireshark の protocol decoding engine は使いますが、desktop GUI は必要なく、学習対象でもありません。

challenge は live malware を解析したり実在 C2 に接続したりしますか?

いいえ。simulated DNS/HTTP evidence を含む prepared suspicious_traffic.pcap を読みます。malware を実行せず、external command-and-control system に通信しません。

HTTPS などの encrypted session を decrypt しますか?

いいえ。decoded metadata と意図的に readable な DNS/HTTP traffic を調べます。session key は提供せず TLS decryption も扱わないため、encrypted application payload は対象外です。

講師

labby
Labby
Labby is the LabEx teacher.