Detecting Sniffers on an Ethernet Network Part I. – the Theory
نویسنده
چکیده
Although wireless networks are spreading quickly nowadays, we find wired Ethernet networks in most institutes, offices and homes. This way most PCs are connected to an Ethernet network. Ethernet networks can be eavesdropped. The act of eavesdropping a network is called sniffing. Sniffing an Ethernet network does not require any special hardware or particularly advanced computer knowledge. Many sensitive data are transmitted unencrypted in practice nowadays. For example, emails, some of the passwords and all of our HTTP requests can be easily read by a sniffer connected to our network. This means sniffing has a serious impact on privacy and secrecy. These simple sniffers can be detected on a network by various methods. This paper presents some of this methods, and discusses the networking fundamentals of these methods. Bár a vezetéknélküli hálózatok gyors fejlődésben vannak, a legtöbb intézményben, irodában és otthonban vezetékes Ethernet hálózatot találunk. Ilyenformán a legtöbb személyi számítógép Ethernet hálózathoz csatlakozik. Az Ethernet hálózatok lehallgathatók. A hálózat lehallgatását sniffingnek (szimatolás) nevezzük. Egy Ethernet hálózat lehallgatásához nem szükséges speciális hardver vagy különösebb számítástechnikai ismeret. Sok bizalmas információ kódolatlanul kerül továbbításra: az emailek, némely jelszavak és az összes HTTP kérés könnyen lehallgathatók egy sniffer segítségével. Ilyenformán a sniffingnek komoly jelentősége van a személyes és titkos információk tekintetében. Ezek az egyszerű snifferek különféle módokon detektálhatók. Jelen írás bemutat néhányat ezek közül, illetve szükséges hálózati ismereteket tárgyalja.
منابع مشابه
Promiscuous Mode Detection Platform
Among various types of attacks on an Ethernet network, “sniffing attack” is probably one of the most difficult attacks to handle. Sniffers are programs that allow a host to capture any packets in an Ethernet network, by putting the host’s Network Interface Card (NIC) into the promiscuous mode. When a host’s NIC is in the normal mode, it captures only the packets sent to the host. Since many bas...
متن کاملRobust Detection of Unauthorized Wireless Access Points
Unauthorized 802.11 wireless access points (APs), or rogue APs, such as those brought into a corporate campus by employees, pose a security threat as they may be poorly managed or insufficiently secured. An attacker in the vicinity may easily get onto the internal network through a rogue AP, bypassing all perimeter security measures. Existing detection solutions do not work well for detecting r...
متن کاملArchitecture of a Novel High Performance Traffic Capturing Device Based on the Intel IXP2400 Network Processor
The extensive availability of cost effective commodity PC hardware pushed the development of flexible and versatile traffic monitoring software such as protocol analyzers, protocol dissectors, traffic sniffers, traffic characterizers and IDSs (Intrusion Detection Systems). The largest part of these pieces of software is based on the well known libpcap API, which in the last few years has become...
متن کاملDetecting MAC Layer Misbehavior in Wifi Networks By Co-ordinated Sampling of Network Monitoring
We present an approach to detect a selfish node in a wireless network by passive monitoring. This does not require any access to the network nodes. Our approach requires deploying multiple sniffers across the network to capture wireless traffic traces among multiple channels. IEEE 802.11 networks support multiple channels and a wireless interface can monitor only a single channel at one time. T...
متن کاملAn Innovative System for Full-Management of CB Using Current Injection Method
In this article, an innovative supervision system will be proposed that can observe and analyze health of Circuit Breaker’s trip coil. The proposed design also logs changes in the coil's quality and informs network supervisor in case of Circuit Breaker (CB) failure. This system injects small direct currents to the Circuit Breaker connections and the trip coil to compute CB’s health and characte...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013