Open Source Security Tools : Practical Guide to Security Applications part 22. Few frontline system administrators can afford to spend all day worrying about security. But in this age of widespread virus infections, worms, and digital attacks, no one can afford to neglect network defenses. Written with the harried IT manager in mind, Open Source Security Tools is a practical, hands-on introduction to open source security tools. | Page 189 Thursday June 24 2004 11 47 AM TCP IP Packet Headers 189 Once you have set your options click OK and your session will start. A window will appear that tracks the session statistics in real time see Figure . If you set your session to show packets in real time you will see them as they come across the wire in the window see Figure . You can stop your session at any time by clicking Stop in the statistic window or choosing Stop from the Capture menu. If you set a limit in the options it will automatically stop when it reaches it. You can now analyze and manipulate your session results. By clicking on the headings at the top of the window you can resort the results by that heading so you can sort the output by source address destination protocol or the info fields. This helps to organize things if you are looking for a specific kind of traffic for example all the DNS queries or all the mail-related traffic. Of course you could also write a filter to capture only this kind of traffic in the first place. Display Options Table lists the commands on the Display menu that you can use to affect how the packets are displayed on the screen. Ethereal Tools There are several built-in analytical tools included with Ethereal. It is also built with a plug-in architecture so that other programs can interact with Ethereal or you can write your own. You can access these options under the Tools menu see Table . Figure Ethereal Session Statistics Window Page 190 Thursday June 24 2004 11 47 AM 190 Chapter 6 Network Sniffers Table Ethereal Display Menu Options Menu Options Descriptions Options submenu This where you can set some global settings such as how the time field is calculated. You can also set automatic scrolling of traffic and name resolution to on since they are turned off by default. Colorize display You can select certain kinds of packet to shade different colors. This makes the display easier to read and pick