Forum Discussion
pschmidt
Bronze II
3 months agoDDOS Analysis: UDP Flood (Question 8)
I'm working through the DDoS UDP Analysis lab and am currently stuck on question 8. I've used both the Statistics > Summary tool within Wireshark and also capinfos to try to determine the total length of the DDoS attack. However the time difference I'm coming up with through both methods is not the correct answer. Any suggestions?
2 Replies
- barney
Bronze II
There probably various and cleverer ways of doing it, but I just looked in the Conversations window for the UDP stream. Here it will give you the relative start time for each conversation and its duration - you're interested in the values for the final conversation record. HTH.
- netcat
Silver III
If you have a duration of a.bc68 then round up to a.bc70
Wireshark shows, depending on the tab, both numbers.