Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Passive Network Analysis
Stephen Barish

In sports, it's pretty much accepted wisdom that home teams have the advantage; that's why teams with winning records on the road do so well in the playoffs. But for some reason we rarely think about "the home field advantage" when we look at defending our networks. After all, the best practice in architecting a secure network is a layered, defense-in-depth strategy. We use firewalls, DMZs, VPNs, and configure VLANs on our switches to control the flow of traffic into and through the perimeter, and use network and host-based IDS technology as sensors to alert us to intrusions.

Comments Mode:
Passive Network Analysis 2007-09-30
Anonymous
A great tool that can be used to perform passive OS fingerprinting in Windows is NetworkMiner. It uses the OS signature databases from both p0f and Ettercap. NetworkMiner can also extract files sent over the network in a similar manner as York and NetworkActiv, but better since NetworkMiner also can extract files from PCAP files (previously captured packets) for off-line analyzis.

NetworkMiner is open source and available at:

http://sourceforge.net/projects/networkminer

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1894/969#969
Passive Network Analysis 2007-10-14
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus