Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File...

34
Evolution of Message Analyzer and Windows Interoperability Paul Long Microsoft

Transcript of Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File...

Page 1: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Evolution of Message Analyzer and Windows Interoperability

Paul Long Microsoft

Page 2: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

2

What is Message Analyzer?

blogs.technet.com/MessageAnalyzer

Page 3: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Page 4: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

What is Message Analyzer

Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data

Trace Collection Tool Remote and Local ETW events

4

Page 5: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Demo: A quick tour

5

Start Page News

Page 6: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Demo: A quick tour

6

Start Page Settings

Synchronized

Not Synchronized

Page 7: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Demo: A quick tour

7

Page 8: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Demo: A quick tour

8

Page 9: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Demo: A quick tour

9

Trace Viewer

Message Stack Tool

Message Detail Tool

Various Stacked Tools

View Filter Tool

Session Tool

Status Bar

Viewer Actions

Page 10: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Demo: A quick tour

10

Page 11: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Demo: A quick tour

11

Page 12: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

12

Demo: Correlation with

Multiple Logs

Page 13: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Page 14: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Page 15: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Differences – Netmon

TCP (135)

Ethernet

IPv4

SMB Req (partial)

TCP (135)

Ethernet

IPv4

TCP (135)

Ethernet

IPv4

TCP (135)

Ethernet

IPv4

SMB Resp

Page 16: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Differences – Wireshark

TCP (135)

Ethernet

IPv4

SMB Req (Reassembled)

TCP (135)

Ethernet

IPv4

TCP (135)

Ethernet

IPv4

TCP (135)

Ethernet

IPv4

SMB Resp

Page 17: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Differences – Message Analyzer

TCP

Ethernet

IPv4

SMB Req (Reassembled)

TCP

Ethernet

IPv4

TCP

Ethernet

IPv4

TCP

Ethernet

IPv4

SMB Resp ReassembledTCP

(meta)

SMB Operation Summary of Request and Response Top Level

Protocol

Top Level Operation

Page 18: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Message Analyzer

Network Moniotr

Wireshark

Page 19: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Differences – Message Analyzer

TCP

Ethernet

IPv4

SMB Req (Reassembled)

TCP

Ethernet

IPv4

TCP

Ethernet

IPv4

TCP

Ethernet

IPv4

SMB Resp ReassembledTCP

(meta)

Top Level Protocol

Hide Operation

Page 20: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Differences – Message Analyzer

TCP (135)

Ethernet

IPv4

SMB Req (Reassembled)

TCP (135)

Ethernet

IPv4

TCP (135)

Ethernet

IPv4

TCP (135)

Ethernet

IPv4

SMB Resp ReassembledTCP

(meta) TCP Viewpoint

SMB Operation Summary of Request and Response Top Level

Protocol

Top Level Operation

Page 21: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Differences – Message Analyzer

TCP (135)

Ethernet

IPv4

TCP (135)

Ethernet

IPv4

TCP (135)

Ethernet

IPv4

TCP (135)

Ethernet

IPv4

TCP Viewpoint

SMB Operation SMB Operation SMB Operation SMB Operation

Top Level Summary Property

Page 22: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Differences – Message Analyzer in 3D

Ethernet Ethernet Ethernet Ethernet

Ethernet Ethernet Ethernet Ethernet

Ethernet Ethernet Ethernet Ethernet

Ethernet Ethernet Ethernet Ethernet

IPv4 IPv4

IPv4 ARP

ARP IPv4

ARP

ARP

IPv4

IPv4IPv4

IPv4 IPv4 ARP

IPv4

IPv4

TCP TCP TCP

TCP

TCP TCP

TCP TCP

TCP

TCP

TCPTCP VIEWPOINT

TLS HTTP Chunk

TLS

TLS

TLS

HTTP Chunk

SMBResponse

ReassembledTCP

SMBRequest

HTTP Response

HTTP Request

Network:192.168.1.10-192.168.1.20Transport: 443-3333

Network:192.168.1.10-65.55.206.228Transport: 80-2515

Network:00-50-8D-B6-CD-56-00-50-8D-B6-CD-66

Network:192.168.1.10-192.168.1.5Transport: 445-9999

C1Network:192.168.1.10-192.168.1.20Transport: 443-3333

C2Network:192.168.1.10-65.55.206.228Transport: 80-2515

C3Network:00-50-8D-B6-CD-56-00-50-8D-B6-CD-66

C4Network:192.168.1.10-192.168.1.5Transport: 445-9999

1s

2s

3s

4s

Page 23: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Differences – Message Analyzer in 3D

Ethernet Ethernet Ethernet

Ethernet Ethernet

Ethernet Ethernet Ethernet

Ethernet Ethernet Ethernet

IPv4 IPv4

IPv4

IPv4

IPv4

IPv4IPv4

IPv4 IPv4

IPv4

IPv4

TCP TCP TCP

TCP

TCP TCP

TCP TCP

TCP

TCP

TCP

Network:192.168.1.10-192.168.1.20Transport: 443-3333

Network:192.168.1.10-65.55.206.228Transport: 80-2515

Network:00-50-8D-B6-CD-56-00-50-8D-B6-CD-66

Network:192.168.1.10-192.168.1.5Transport: 445-9999

C1Network:192.168.1.10-192.168.1.20Transport: 443-3333

C2Network:192.168.1.10-65.55.206.228Transport: 80-2515

C3Network:00-50-8D-B6-CD-56-00-50-8D-B6-CD-66

C4Network:192.168.1.10-192.168.1.5Transport: 445-9999

1s

2s

3s

4s

Page 24: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Differences: Session Explorer

24

Total number of messages at the bottom. For a .cap or .pcap. This is

what Netmon/Wireshark display

Total Number after data is reassembled and summarized with

operations.

Page 25: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Page 26: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Dealing with Encrypted Traffic

Capture before encryption HTTPs IPSEC SMB SMB Direct

Decrypt a trace afterwards

26

Page 27: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

27

Demo: Post Decryption

Page 28: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Decrypting a trace

28

Page 29: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Decrypting a trace

29

Decryption Tool can be docked anywhere.

1

2

Page 30: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Decrypting a trace

30

3. Decrypted Traffic for the in focus

selected message

1. Select successfully decrypted session

from Decryption Tool

2. This triggers a global selection of those messages

Page 31: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Decrypting a trace

31

Selection Tool Window is a helpful way to find all the

selected messages and bring each one in focus.

Page 32: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Decrypting a trace

32

Page 33: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Questions? 33

Page 34: Evolution of Message Analyzer and Windows …...What is Message Analyzer Protocol and Log File Analysis Tool Correlation across traces and logs Visualize Data ...

2014 Storage Developer Conference. © Microsoft. All Rights Reserved.

Resources

http://blogs.technet.com/MessageAnalyzer http://social.technet.microsoft.com/Forums/en-

US/home?forum=messageanalyzer http://connect.Microsoft.com/Site216

34