The cloud shark thing looks like a good tool. It decides traffic and presents it nicely. I'll have to dig into it further to find out whether it can actually summarise things.
Andrews and Arnold can do a packet capture for me and decode it (tcpdump or similar) outputting it as a fairly overwhelming amount of not-very-friendly ascii. What I would really like to see is a dramatically reduced amount of data, who are the communicants, what protocols are in use, do DNS lookups perhaps, assign names to/enumerate nameless addresses. That kind of thing. Where there is a huge amount going on, bring it down to a readable amount of information. Spotting scans would be nice too.