Overview
Hypertext Transfer Protocol (HTTP) powers most web apps and APIs. From a PCAP/PCAPNG you can pinpoint why pages or endpoints are slow: DNS or TLS delays, long TTFB/server think-time, redirect chains, cache misses, missing compression, bloated headers/cookies, and HTTP/2 or HTTP/3 behavior under loss. Even when payloads are encrypted, metadata such as ALPN, SNI, and timing reveals transport and protocol dynamics.
- What you’ll see: TTFB and handshake timing, redirect chains, status code trends, cache/compression hints, H2 multiplexing patterns, H3 retries/fallbacks, TLS/ALPN negotiation.
- Best for: Performance analysis, NOC troubleshooting, SOC triage, incident response.
- Works with: TLS over TCP, HTTP/2 on TLS, HTTP/3 over QUIC/UDP, CDNs and reverse proxies.
What to look for
- Slow starts: high DNS/TLS time, no TLS resumption, ALPN negotiation delays,
- TTFB & server think-time: long waits before first byte or between responses,
- Redirect chains: multiple 301/302→200 hops; mixed HTTP↔HTTPS,
- Cache/compression: repeated downloads, missing
Cache-Control/ETag; no gzip/br on large text assets,
- HTTP/2 quirks: many small sequential streams (poor prioritization), Head-of-line (HOL) blocking effects under loss,
- HTTP/3 signals: QUIC handshake retries, UDP/443 blocked → fallback to HTTP/2/1.1,
- Header/cookie bloat: oversized request headers or cookies causing latency,
- Error patterns: bursts of 4xx/5xx, CORS failures, CDN edge vs origin differences.
Capture tips
- Capture near the client for UX timing and near the gateway for egress/CDN behavior.
- Include DNS and TLS traffic to correlate name resolution and handshakes with HTTP timing.
- For HTTPS payload visibility, use decryption keys or pre-decrypted captures when policy allows.
- Record a focused window that reproduces the issue (keeps files within the 10 MB demo limit).
- Disable NIC offloads on capture interfaces to preserve accurate timing and sizes.
Example walkthrough
- Browse to the domain/app (http, tls, dns).
- Check DNS → TLS → TTFB timing; confirm ALPN (H2/H3) and TLS resumption.
- Identify redirect chains and status code spikes; note mixed content or protocol downgrades.
- Evaluate cache/compression (headers if decrypted; otherwise infer from sizes and repeats).
- For HTTP/2, inspect stream concurrency and HOL symptoms under loss.
- For HTTP/3, look for QUIC retries or fallback to TCP to the same host.
- Export flows and timing with a brief summary for the ticket.
HTTP FAQ
Start with DNS and TLS timing, then TTFB and server think-time. Check redirect chains, cache/compression, and large assets. Use ALPN to see if H2/H3 was negotiated; retries or fallbacks hint at interference.
H1.1 uses multiple TCP connections; H2 multiplexes many streams over one TCP connection; H3 runs over QUIC/UDP and avoids TCP head-of-line blocking but can be blocked by middleboxes.
Without keys, content is opaque, but TLS timing, ALPN, SNI, versions/ciphers, and retry patterns still reveal a lot. With keys or decrypted captures, header and status analysis is available.
For plaintext HTTP, inspect Cache-Control/ETag and Content-Encoding. For HTTPS, infer from repeated downloads and object sizes, or analyze decrypted captures.
Blocking of UDP/443, QUIC version negotiation issues, or middlebox policies can force fallback. Look for QUIC handshake retries followed by new TCP connections to the same host.