How to automate Packet analysis

The tutorial explains how to automate packet analysis. Packet analysis is a technique where protocol analyzers are used to capture packets and later look for specific patterns. Packet analysis can be performed by the use of tools like wireshark and the tester can use appropriate filters. Packet analysis automation is technique where the pattern is searched programatically by the use of custom scripts/programs.

For this purpose, tshsark, which is a command line analyzer, is setup and installed and the required packets captured. The captured packets are output to a text file. For searching for the specific pattern, a tool can be developed with Python/TCL with the use of regular expressions. Regular expressions are used specifically to look for patterns in a file and display the output.

