Personally, I would shy away from the I/O graph and instead make use of the tcptrace graph. It is a little hard to read at first, but there are some great explanations of it online. To get to the tcptrace graph, in Wireshark go to Statistics > TCP Stream Graphs > Time Sequence (tcptrace). Again, you'll likely want some additional explanation of how it works, so search around for some good resources on the web. Hope this helps!