Protocol · HTTP

HTTP PCAP Analysis

by My Network Consultant

From capture to clarity—optimize HTTP/1.1, HTTP/2, and HTTP/3 with AI-powered insights.

Layer 7 (Application) Related: TCP, TLS, DNS, QUIC Common ports: 80/TCP, 443/TCP (H3 over UDP/443)

Overview

Hypertext Transfer Protocol (HTTP) powers most web apps and APIs. From a PCAP/PCAPNG you can pinpoint why pages or endpoints are slow: DNS or TLS delays, long TTFB/server think-time, redirect chains, cache misses, missing compression, bloated headers/cookies, and HTTP/2 or HTTP/3 behavior under loss. Even when payloads are encrypted, metadata such as ALPN, SNI, and timing reveals transport and protocol dynamics.

  • What you’ll see: TTFB and handshake timing, redirect chains, status code trends, cache/compression hints, H2 multiplexing patterns, H3 retries/fallbacks, TLS/ALPN negotiation.
  • Best for: Performance analysis, NOC troubleshooting, SOC triage, incident response.
  • Works with: TLS over TCP, HTTP/2 on TLS, HTTP/3 over QUIC/UDP, CDNs and reverse proxies.

What to look for

  • Slow starts: high DNS/TLS time, no TLS resumption, ALPN negotiation delays,
  • TTFB & server think-time: long waits before first byte or between responses,
  • Redirect chains: multiple 301/302→200 hops; mixed HTTP↔HTTPS,
  • Cache/compression: repeated downloads, missing Cache-Control/ETag; no gzip/br on large text assets,
  • HTTP/2 quirks: many small sequential streams (poor prioritization), Head-of-line (HOL) blocking effects under loss,
  • HTTP/3 signals: QUIC handshake retries, UDP/443 blocked → fallback to HTTP/2/1.1,
  • Header/cookie bloat: oversized request headers or cookies causing latency,
  • Error patterns: bursts of 4xx/5xx, CORS failures, CDN edge vs origin differences.

Capture tips

  • Capture near the client for UX timing and near the gateway for egress/CDN behavior.
  • Include DNS and TLS traffic to correlate name resolution and handshakes with HTTP timing.
  • For HTTPS payload visibility, use decryption keys or pre-decrypted captures when policy allows.
  • Record a focused window that reproduces the issue (keeps files within the 10 MB demo limit).
  • Disable NIC offloads on capture interfaces to preserve accurate timing and sizes.

Example walkthrough

  1. Browse to the domain/app (http, tls, dns).
  2. Check DNS → TLS → TTFB timing; confirm ALPN (H2/H3) and TLS resumption.
  3. Identify redirect chains and status code spikes; note mixed content or protocol downgrades.
  4. Evaluate cache/compression (headers if decrypted; otherwise infer from sizes and repeats).
  5. For HTTP/2, inspect stream concurrency and HOL symptoms under loss.
  6. For HTTP/3, look for QUIC retries or fallback to TCP to the same host.
  7. Export flows and timing with a brief summary for the ticket.

HTTP FAQ

Start with DNS and TLS timing, then TTFB and server think-time. Check redirect chains, cache/compression, and large assets. Use ALPN to see if H2/H3 was negotiated; retries or fallbacks hint at interference.

H1.1 uses multiple TCP connections; H2 multiplexes many streams over one TCP connection; H3 runs over QUIC/UDP and avoids TCP head-of-line blocking but can be blocked by middleboxes.

Without keys, content is opaque, but TLS timing, ALPN, SNI, versions/ciphers, and retry patterns still reveal a lot. With keys or decrypted captures, header and status analysis is available.

For plaintext HTTP, inspect Cache-Control/ETag and Content-Encoding. For HTTPS, infer from repeated downloads and object sizes, or analyze decrypted captures.

Blocking of UDP/443, QUIC version negotiation issues, or middlebox policies can force fallback. Look for QUIC handshake retries followed by new TCP connections to the same host.
We use cookies & process data
By using this site, you agree to our Terms and Privacy Policy. We process file uploads for network analysis only.