Establishing a baseline
Establishing a baseline is a task you must perform. It might sound difficult, but it's very simple when you know your network. In this section, we will talk about the common protocols that run in a typical enterprise network, and we will look at their typical traffic patterns.
Protocols that are common to enterprise networks can be categorized into several groups, as follows:
- Internet access protocols—HTTP, HTTP Secure (HTTPS), Google QUIC (GQUIC), SMTP, POP, and DNS
- Organizational applications—NetBIOS/SMB, Microsoft Terminal Services (MS-TS), database applications, and multicasts
- Network protocols—Routing protocols, discovery protocols, monitoring protocols, and so on
Let's see some typical capture files and find out what we should see in organizational networks.
Small business/home network
In the following screenshot, we see a typical protocol hierarchy of a user connected to an organizational...