Metadata-Based Characterization of Day–Night Internet Traffic Using Wireshark Capture and Python/Jupyter Analysis

Wireshark Network traffic analysis Metadata-based traffic analysis Packet-level analysis Day–night traffic comparison Python-based visualization QUIC protocol

Authors

  • Marwa K. Hasan Technical Engineering College - Kirkuk, Northern Technical University, Kirkuk, 36001, Iraq
June 19, 2026
June 22, 2026

Downloads

This study presents a packet level analysis of daytime and nighttime Internet traffic using Wireshark and processing in Python using Anaconda/Jupyter Notebook based on metadata. Three representative Internet scenarios were studied: a university website, a scientific website, and an educational YouTube video-streaming scenario. In each scenario, packet traffic was captured twice – on the same day, once during the day and once during the night. The acquired records were exported from Wireshark in CSV format and analyzed by means of several traffic indicators, e.g., total packet number, traffic volume, mean packet length, packet-size distribution, cumulative packet behavior, protocol composition and correlation patterns of packet rate and traffic volume. The results showed that the day-night traffic variation was highly dependent on the type of accessed service. For the University website packet count fell from 21760 during the day to 17250 at night, traffic volume fell from 17.99 MB to 10.78 MB. Scientific website also showed a reduction from 13887 to 10218 packets and 9.15 MB to 6.07 MB respectively. But YouTube traffic was increased at night with packet count increased from 25112 to 26875 and traffic volume increased from 21.46 MB to 24.84 MB. Protocol analysis showed that TCP and TLSv1.3 were dominant in University and Scientific traffic, whereas YouTube traffic showed a higher proportion of UDP and QUIC, especially in nighttime capture. Correlation analysis further confirmed that each website category produced a distinct temporal traffic signature. Overall, the proposed framework provides a reproducible and privacy-preserving approach for analyzing day–night Internet traffic behavior using Wireshark-captured metadata and Python-based visualization.