Metadata-Based Characterization of Day–Night Internet Traffic Using Wireshark Capture and Python/Jupyter Analysis
Downloads
This study presents a packet level analysis of daytime and nighttime Internet traffic using Wireshark and processing in Python using Anaconda/Jupyter Notebook based on metadata. Three representative Internet scenarios were studied: a university website, a scientific website, and an educational YouTube video-streaming scenario. In each scenario, packet traffic was captured twice – on the same day, once during the day and once during the night. The acquired records were exported from Wireshark in CSV format and analyzed by means of several traffic indicators, e.g., total packet number, traffic volume, mean packet length, packet-size distribution, cumulative packet behavior, protocol composition and correlation patterns of packet rate and traffic volume. The results showed that the day-night traffic variation was highly dependent on the type of accessed service. For the University website packet count fell from 21760 during the day to 17250 at night, traffic volume fell from 17.99 MB to 10.78 MB. Scientific website also showed a reduction from 13887 to 10218 packets and 9.15 MB to 6.07 MB respectively. But YouTube traffic was increased at night with packet count increased from 25112 to 26875 and traffic volume increased from 21.46 MB to 24.84 MB. Protocol analysis showed that TCP and TLSv1.3 were dominant in University and Scientific traffic, whereas YouTube traffic showed a higher proportion of UDP and QUIC, especially in nighttime capture. Correlation analysis further confirmed that each website category produced a distinct temporal traffic signature. Overall, the proposed framework provides a reproducible and privacy-preserving approach for analyzing day–night Internet traffic behavior using Wireshark-captured metadata and Python-based visualization.
M. N. Ashaari, M. Kassim, R. Ab. Rahman, and A. R. Mahmud, “Performance Analysis on Multiple Device Connections of Small Office Home Office Network,” Baghdad Science Journal, vol. 18, no. 4(Suppl.), pp. 1457–1464, 2021, doi: 10.21123/bsj.2021.18.4(Suppl.).1457.
R. Tuli, “Analyzing Network Performance Parameters Using Wireshark,” International Journal of Network Security & Its Applications, vol. 15, no. 1, pp. 1–13, 2023, doi: 10.5121/ijnsa.2023.15101.
Wireshark Foundation, “Wireshark User’s Guide,” official documentation, accessed May 2026.
Anaconda, Inc., “Anaconda Navigator Documentation,” official documentation, accessed May 2026.
Project Jupyter, “Jupyter Notebook Documentation,” official documentation, accessed May 2026.
E. Papadogiannaki and S. Ioannidis, “A Survey on Encrypted Network Traffic Analysis: Applications, Techniques, and Countermeasures,” ACM Computing Surveys, vol. 54, no. 6, Article 123, pp. 1–35, 2021, doi: 10.1145/3457904.
C. Oh, J. Ha, and H. Roh, “A Survey on TLS-Encrypted Malware Network Traffic Analysis Applicable to Security Operations Centers,” Applied Sciences, vol. 12, no. 1, Article 155, 2022, doi: 10.3390/app12010155.
J. Iyengar and M. Thomson, “QUIC: A UDP-Based Multiplexed and Secure Transport,” RFC 9000, Internet Engineering Task Force, 2021, doi: 10.17487/RFC9000.
M. Bishop, “HTTP/3,” RFC 9114, Internet Engineering Task Force, 2022, doi: 10.17487/RFC9114.
L. F. Sikos, “Packet analysis for network forensics: A comprehensive survey,” Forensic Science International: Digital Investigation, vol. 32, Article 200892, 2020, doi: 10.1016/j.fsidi.2019.200892.
N. A. L. Mabsali, H. Jassim, and J. Mani, “Effectiveness of Wireshark Tool for Detecting Attacks and Vulnerabilities in Network Traffic,” in Proceedings of the 1st International Conference on Innovation in Information Technology and Business (ICIITB 2022), Advances in Computer Science Research, vol. 104, pp. 114–135, 2023, doi: 10.2991/978-94-6463-110-4_10.
M. Karamollahi, C. Williamson, and M. Arlitt, “Packet-Level Analysis of Zoom Performance Anomalies,” in Proceedings of the 2023 ACM/SPEC International Conference on Performance Engineering, pp. 221–232, 2023, doi: 10.1145/3578244.3583725.
F. Loh, F. Wamser, F. Poignée, S. Geißler, and T. Hoßfeld, “YouTube Dataset on Mobile Streaming for Internet Traffic Modeling and Streaming Analysis,” Scientific Data, vol. 9, Article 293, 2022, doi: 10.1038/s41597-022-01418-y.
S. Chellappa and R. Bartos, “Is QUIC Quicker with HTTP/3? An Empirical Analysis of Quality of Experience with DASH Video Streaming,” in 2022 IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS), 2022, doi: 10.1109/ANTS56424.2022.10227765.
J. S. Sidhu and A. Bentaleb, “Video Streaming Over QUIC: A Comprehensive Study,” ACM Transactions on Multimedia Computing, Communications, and Applications, 2026, doi: 10.1145/3793674.
