Forensic pcap Analysis: Difference between revisions

From Allegro Network Multimeter Manual
Jump to navigation Jump to search
Access restrictions were established for this page. If you see this message, you have no access to this page.
(Created page with "== ''' Problem''' == ------- How can you use the *Allegro Network Multimeter* for forensic analysis? As an example, you would like to process a recorded Pcap file with the *A...")
 
No edit summary
 
(19 intermediate revisions by 6 users not shown)
Line 1: Line 1:
== ''' Problem''' ==
== Problem ==
-------
How can you use the Allegro Network Multimeter for forensic analysis?
As an example, you would like to process a recorded pcap file with the
Allegro Network Multimeter.


How can you use the *Allegro Network Multimeter* for forensic analysis?
== Note ==
As an example, you would like to process a recorded Pcap file with the
By default, when in bridge mode (in-line), the Allegro Network Multimeter will NOT forward or process any network traffic while loading a pcap file for analysis. In other words, A network Link will go down until pcap analysis is finished and normal operational mode is restored.
*Allegro Network Multimeter* in the lab.


'''This can be resolved''' by enabling our [[Parallel packet processing]] feature. This allows for normal operation and pcap analytics at the same time.


== ''' Warning''' ==
Because of varying Allegro Network Multimeter user/usage scenarios and reserved memory allocation, this feature is disabled by default.


== Preparation ==
The preparation of the Allegro Network Multimeter is very simple.
We recommend to use this feature with an activated ring buffer to
allow the extraction of pcap subsets. Simply attach a USB3 disk or, if
installed, use the internal disk as a ring buffer. If it is a USB disk
or USB stick that has not been used before, a popup will be displayed and
will guide you to format the disk and to set up the ring buffer.


== pcap upload ==
To use the Allegro Network Multimeter as a forensic analysis tool, navigate
to "Generic" -> "Pcap analysis".


The *Allegro Network Multimeter* will NOT forward, receive or analyze
{|
any packets while analyzing pcap files. Traffic forwarding in bridge
| [[File:Forensic_pcap_analysis_dash.png|1000px|thumb|right]]
mode is not available until the pcap file has been analyzed completely
|}
and the normal operation mode is restored.


== ''' Preparation''' ==
Here, you can select the pcap file you want to analyze by either dragging it
from your file browser to the drop zone on the page or by clicking into the
drop zone and selecting it via a file chooser dialogue.
 
{|
| [[File:Forensic_pcap_analysis_module.png|1000px|thumb|right]]
|}
 
After a file is selected, click the "Analyze PCAP" button. One of two new modal dialogues will open:


'''Case one''', when parallel packet processing is not activated:


The preparation of the *Allegro Network Multimeter* is very simple.
{|
We recommend to use this feature with an activated ring buffer to
| [[File:Pcap-upload-2.png|600px|thumb|right]]
allow the extraction of pcap subsets. Simply attach a USB3 disk or, if
|}
installed, use the internal disk as a ring buffer. If it is a USB disk
 
or stick that has not been used before, a popup will be displayed and
If you want to keep processing and forwarding packets while analysing the PCAP then consider enabling the Parallel packet processing feature.
will guide you to format the disk and to set up the ring buffer.


== ''' Pcap upload''' ==




To use the *Allegro Network Multimeter* as a forensic analysis tool, navigate
'''Case two''', when parallel packets processing is activated:
to "Generic" -> "Pcap analysis" and press pcap upload.


.. image:: pics/pcap-upload-1.png
{|
| [[File:Forensic_pcap_analysis_parallel_processing.png|600px|thumb|right]]
|}


Here, you can select the pcap file you want to analyze by either dragging it
'''Meaning of each setting:'''
from your file browser to the drop zone on the page or by clicking into the
drop zone and selecting it via a file chooser dialog.


After a file is selected, click the "Upload and analyze pcap" button. A new
'''Slot:'''  Choose the replay slot the analysis should run at.
modal dialog will open:


.. only:: html
'''Storage Device:''' Choose the storage device, where the PCAP-file will be uploaded to. Using the [[Packet ring buffer]] enables you to re-download the packets later.  


  .. image:: pics/pcap-upload-2.png
'''Stop if DB full:''' When enabled will automatically stop the PCAP upload, if the in-memory DB is full. Packets will be lost if the DB is exceeded, while this option is not enabled.


.. only:: latex


  .. image:: pics/pcap-upload-2.png
:scale: 40%
:align: center


Please carefully read the warnings and consider if you want to use the capture
ring buffer.


If you activate the capture ring buffer, it is easy to extract certain parts of
If you activate the capture ring buffer, it is easy to extract certain parts of
the pcap using the measurement modules of the *Allegro Network Multimeter*. All
the pcap using the Allegro Network Multimeter measurement modules. All
pcap download buttons will extract the specified parts as with live network
pcap download buttons will extract the specified data as with a live network
traffic.
traffic.


After starting confirming the dialog, the upload will start


.. image:: pics/pcap-upload-3.png


The table at the bottom of the page will show you the upload progress. Even with
After starting confirming the dialogue, the upload will begin.
upload still in progress, you can switch to some measurement module and
 
{|
| [[File:Forensic_pcap_analysis_finish_upload.png|1000px|thumb|right]]
|}
 
The table at the bottom of the page will indicate the upload progress. Even with
an upload still in progress, you can switch to another measurement module and
investigate the contents of the pcap file.
investigate the contents of the pcap file.


.. raw:: latex
When the upload is finished, other statistics in the Allegro Network Multimeter will now show data from this pcap-file.


    \clearpage
To return to the live data analysis, simply press the 'Finish replay' button.

Latest revision as of 06:25, 23 May 2025

Problem

How can you use the Allegro Network Multimeter for forensic analysis? As an example, you would like to process a recorded pcap file with the Allegro Network Multimeter.

Note

By default, when in bridge mode (in-line), the Allegro Network Multimeter will NOT forward or process any network traffic while loading a pcap file for analysis. In other words, A network Link will go down until pcap analysis is finished and normal operational mode is restored.

This can be resolved by enabling our Parallel packet processing feature. This allows for normal operation and pcap analytics at the same time.

Because of varying Allegro Network Multimeter user/usage scenarios and reserved memory allocation, this feature is disabled by default.

Preparation

The preparation of the Allegro Network Multimeter is very simple. We recommend to use this feature with an activated ring buffer to allow the extraction of pcap subsets. Simply attach a USB3 disk or, if installed, use the internal disk as a ring buffer. If it is a USB disk or USB stick that has not been used before, a popup will be displayed and will guide you to format the disk and to set up the ring buffer.

pcap upload

To use the Allegro Network Multimeter as a forensic analysis tool, navigate to "Generic" -> "Pcap analysis".

Forensic pcap analysis dash.png

Here, you can select the pcap file you want to analyze by either dragging it from your file browser to the drop zone on the page or by clicking into the drop zone and selecting it via a file chooser dialogue.

Forensic pcap analysis module.png

After a file is selected, click the "Analyze PCAP" button. One of two new modal dialogues will open:

Case one, when parallel packet processing is not activated:

Pcap-upload-2.png

If you want to keep processing and forwarding packets while analysing the PCAP then consider enabling the Parallel packet processing feature.


Case two, when parallel packets processing is activated:

Forensic pcap analysis parallel processing.png

Meaning of each setting:

Slot: Choose the replay slot the analysis should run at.

Storage Device: Choose the storage device, where the PCAP-file will be uploaded to. Using the Packet ring buffer enables you to re-download the packets later.

Stop if DB full: When enabled will automatically stop the PCAP upload, if the in-memory DB is full. Packets will be lost if the DB is exceeded, while this option is not enabled.



If you activate the capture ring buffer, it is easy to extract certain parts of the pcap using the Allegro Network Multimeter measurement modules. All pcap download buttons will extract the specified data as with a live network traffic.


After starting confirming the dialogue, the upload will begin.

Forensic pcap analysis finish upload.png

The table at the bottom of the page will indicate the upload progress. Even with an upload still in progress, you can switch to another measurement module and investigate the contents of the pcap file.

When the upload is finished, other statistics in the Allegro Network Multimeter will now show data from this pcap-file.

To return to the live data analysis, simply press the 'Finish replay' button.