Solera DataEcho
I came across this press release from Solera Networks on their open source DataEcho application. DataEcho is a Windows program that captures live traffic or reads traces in Libpcap format. It's best used for interpreting Web traffic, as shown in this screen capture of a visit to www.bejtlich.net recorded in Wireshark and fed to DataEcho.
My Web site doesn't render that well because it uses CSS, but you can see how DataEcho breaks down the Web traffic. This is a similar view from Wireshark, sorted on the last column.
Besides DataEcho, I found a SourceForge project page for a Solera-related "tEthereal Network Forensic Console", which says:
Management Console to reconstruct emails, web sessions, VOIP sessions, FTP, and all known supported Internet Protocols for Network Forensics. ***UPDATE*** Project release scheduled.
That looks interesting, but no files are available. I have been exchanging emails with Solera CEO Terry Haas, so I hope to find out more about this company's projects.
My Web site doesn't render that well because it uses CSS, but you can see how DataEcho breaks down the Web traffic. This is a similar view from Wireshark, sorted on the last column.
Besides DataEcho, I found a SourceForge project page for a Solera-related "tEthereal Network Forensic Console", which says:
Management Console to reconstruct emails, web sessions, VOIP sessions, FTP, and all known supported Internet Protocols for Network Forensics. ***UPDATE*** Project release scheduled.
That looks interesting, but no files are available. I have been exchanging emails with Solera CEO Terry Haas, so I hope to find out more about this company's projects.
Comments
We are posting an update to DataEcho on SourceForge this weekend. It has several bug fixes incorporarted and has some code changes to allow it to run under Linux using Mono.
The "tetheral" project is still a mystery to me, after 2 1/2 months on board at Solera ... apparently it's a command line version of Ethereal but I really don't know its status.
Terry
Thanks,
Terry