Experience with PCAP

The packet capture appliances can be used anywhere in the network, however, the most common, are placed at the entrance to the network and in the front of the most important equipment, for example, the servers that have important information. The PCAP is used to capture and record the network packets in full (Bejtlich, 2013). For various appliances, for example, the network forensics and the incident responses, it is important to carry out a full packet capture (Bejtlich, 2013).

The packet capture is able to support some primary network forensic uses, for example the cyber security incidence report, in this case the PCAP enables an understanding of the complete context of the user session to identify the entry point, the path and the affected application and network elements (Bejtlich, 2013). PCAP makes it possible for an examination and assess the native packet flows in order to have an understanding of the specific application transactions or the reconstructs of a user session. The deep packet visibility and the granular back in time historical analysis are also possible through PCAP (Sanders, 2011).

The PCAP can benefit my online experience in many ways; it can help me to capture the data packets that move through a computer network, after they are capture the packets can be analyzed to help in diagnosing and solving the network and application performance and the reliability challenges (Sanders, 2011). The packet capture can help me to determine the network response time by measuring the amount of time that is required to for a packet to move from a sender to a receiver. It can also help me to measure the online application response time.


