From charlesreid1

Advanced Stuff

Endpoints and Conversations

See Wireshark/Conversation Analysis page

Protocols

See the Wireshark/Protocol Analysis page for more info on analyzing traffic protocols.

Name Resolution

To convert from a MAC address to an IP address is name resolution using the ARP protocol.

To convert from IP to Human-readable domain name uses DNS protocol.

Traffic

Wireshark IO graphs show the measure of traffic in a given space over time. By changing the time resolution you get very different pictures of the data.

Case in point: the rather boring 1-second resolution:

WiresharkIO 1second.png

versus the much more interesting 10-minute resolution:

WiresharkIO 10minute.png