Free Essay

Packet Sniffing Prevention

In:

Submitted By RADL
Words 551
Pages 3
Packet Sniffing Prevention

Blocking a Wireless Sniffer-Public Connection

• Disable the automatic connection feature in wireless settings
• Configure a firewall that is automatically installed with Window updates. Enhance the strength of the firewall and increase security settings to “block all incoming connections”
• Confirm the public network’s home page includes a privacy policy. (Networks that use encryption to protect other users from accessing files on the computer will come complete with a privacy policy. Networks that don’t have a privacy statement on the home page do not use encryption.)
• Use sites with ‘https’ at the beginning of the URL instead of ‘http’. The ‘s’ = security

Tips to Defend against Sniffing

• Restrict the physical access to the network media to ensure that a packet sniffer is not able to be installed
• Use encryption to protect confidential information
• Permanetly add MAC address to the gateway to the ARP cache
• Use static IP and static ARP table –prevents attackers from adding the spoofed ARP entries
• Turn off network identification broadcast and restrict the network to authorized users
• Use IPv6 instead of IPv4
• Use encrypted sessions like: SSh, SCP, SSL
• Use security :PGP and S/Mipe, VPN, IPsec, TLS and OTP

Packet Sniffing Prevention

• Best way – Use Encryption
• Secure Socket Layer –encapsulates data with help of original certificates and digital signatures
• IP Security- adds security at packet level. (each packet has a header is encrypted which contains the major information like addresses)
• PGP and MIME: Commonly used Email services. As emails are stored for extended periods, it is best to use them so emails don’t end up in wrong mailboxes.
• VPN (Virtual Private Network – provide encrypted data across the Internet. They are more secure, but if hacked the data may be seen even before encryption.

Anti-Sniffing Tools

• Scan networks to determine if any NICs are running a promiscuous mode
• Run tools regularly
• They act as an alarm triggered by evidence of a sniffer

Crime - Three International Hackers Indicted for “Sniffing” Payment Card Numbers - 5/14/2008

• Hacked electronic cash registers of US restaurant Dave and Busters (D&B) between May and August of 2007
• Stole credit and debit card numbers
• Cost of New York store at least $600,000 and 5,000 credit/debit card numbers stolen
• Illegal accessed 11 national chain servers by installing packet sniffers at each location
• The sniffers “vacuumed up Track 2 data from credit card magstripes as it traveled from the restaurants servers to D&B’s headquarters in Dallas, TX.”
• Track 2 data comprises only the credit/debit card’s numbers, expiration date and security code.
• Names or other personally identifiable information like social security number or bank account numbers were revealed.
• Ken Pappas, security strategist at Top Layer Networks, states the breaches occur as retailers fail to encrypt the card data at the point of the swipe.
• Pappas stated companies don’t encrypt card number sent from cash registers until they reach a centralized location, headquarters. At headquarters they are encrypted and sent to third party for verification. Recommendation: invest in point of swipe encryption.

Sources http://www.ehow.com/how_7354230_block-wireless -sniffer.html

http://luizfirmino.blogspot.com/2011/09/how-tdefen-against-sniffing.hmtl

http:// www.symantec.com/connect/articles/sniffers-what-they-are-and-how-protect-yourself

http://www.securitymanagement.com/news/three-international-hackers-indicted-sniffing-p…

Similar Documents

Free Essay

Csec630 Lab Assignment 2

...either download and use these rules from the Snort website with default settings, or can modify them to his/her network requirements and needs. By changing the default settings of the rules provided on the Snort website, there is a chance that the user might disable packet sniffing on a port that needs to be enabled, causing no alerts on that port. There is also a possibility that user may have set a range of ports to be scanned by Snort IDS for sniffing and the traffic that is coming in the network is not through any of those ports, muting the alerts. 2. If we only went to a few web sites, why are there so many alerts? An Intrusion Detection System (IDS) provides a wide range of monitoring techniques including packet sniffing, file integrity monitoring, and even artificial intelligence algorithms that detect anomalies in network traffic. Snort, a public domain intrusion detection system, monitors traffic by analyzing every packet on a network, looking for malevolent content. It does this by putting the network adaptor in promiscuous mode so that it can see all network traffic on the wire, a process referred to as packet sniffing. Snort is a rule-based IDS, which means that it applies a set of rules to each packet based on known attack signatures. When it detects an attack signature, it performs the action designated in the rule. 3. What are the advantages of logging more information to the alerts file? The advantage of logging more information in the alerts file gives...

Words: 1658 - Pages: 7

Free Essay

Packet Sniffing

...A SEMINAR REPORT ON | PACKET SNIFFER | SUBMITTED BY SUBMITTED ONKUNAL GOPAL THAKUR MAY 14,2010VISHAL SHIRGUPPIJUSTIN FRANCISSHAZIA ALIUNDER THE GUIDANCE OF MR. SUNIL SURVEFR. CONCEICAO RODRIGUES COLLEGE OF ENGINEERINGBANDRA(W)MUMBAI – 400 050 | CERTIFICATE This is to certify that, Mr. KUNAL GOPAL THAKUR , Mr. VISHAL SHIRGUPPI ,Mr. JUSTIN FRANCIS and Ms. SHAZIA ALI have completed their project on PACKET SNIFFER satisfactorily in partial fulfillment under the department of Computer Engineering during academic year 2009-2010. ____________________________ Teacher In-Charge ACKNOWLEDGEMENT We would like to express our sincere thanks and gratitude to our guide Mr. Sunil Surve for his valuable guidance and suggestions. We are highly indebted to him for providing us an excellent opportunity to learn and present our studies in the form of this seminar report. We take this opportunity to thank the members of the teaching and non-teaching staff of Fr.CRCE for the timely help extended by them. Lastly thanking our parents, for their morale support and encouragement. Kunal Gopal Thakur Vishal Shirguppi Justin Francis Shazia Ali ABSTRACT: Packet sniffing is a technique of monitoring every packet that crosses the network. A packet sniffer is a piece of software or hardware...

Words: 3356 - Pages: 14

Free Essay

Security Attack

...Information Systems Security By: Jessica Burnheimer, Kathleen Cline, Brian Weiss Outline for Group paper I. Introduction II. Issues concerning Information Systems Security A. Define IS security B. Why IS security is necessary? C. History and Back round of IS security D. Current issues concerning IS security 1.) Spamming 2.) Hacking 3.) Jamming 4.) Malicious software 5.) Sniffing 6.) Spoofing 7.) Identity Theft III. Solutions to contemporary IS security issues A. Solutions for “Spamming” B. Solutions for “Hacking” C. Solutions for “Jamming” D. Solutions for “Malicious Software” E. Solutions for “Sniffing” F. Solutions for “Spoofing” G. Solutions for “Identity Theft” IV. The Future of Information Systems Security A. New technologies and techniques effecting the future of Information Systems Security B. Tips and information regarding maintaining a Secure Information System C. How security issues will continue to shape Information Systems Management V. Conclusion Abstract The purpose of this paper is to discuss the pressing issues pertaining to Information Systems security. We will be covering the history of Information Systems Security, the current security issues, and why it is important to be knowledgeable in Information Systems security. Also, we will cover some solutions to the issues that...

Words: 4780 - Pages: 20

Premium Essay

Myrtle & Associates/Bellview Law Group to Mab Law Firm Network Integration

...White Paper: This white paper discusses how to choose the integration approach best fitting the needs of Myrtle & Associates and Bellview Law Group in their merging into one law firm: MAB Law Firm. Assumptions: 1. Both Myrtle & Associates & Bellview Law Group Utilized Access To the Internet via a Digital Subscribers Line(DSL) 2. Myrtle & Associates & Bellview Law Group are separated by a considerable geographical distance. 3. Current Novell Servers Used by Bellview Law Group are Old. 4. All internal hard cabling runs will be wired with CAT 5e. Current Network Diagram Please See Exhibit (A-1 & A-2) Diagram of Proposed Network Integration Please See Exhibit (B) Challenges to Integrating the Current LANs, Challenges integrating the Myrtle & Associates and Bellview Law Group networks will be presented by the following: * The geographical distance between the two offices (L2TP/IPsec) * Bellview Law Group use of Novell and IPX/SPX instead of TCP/IP Integrating these two networks will be faced by the geographical distance between the two offices where the law firms reside. One solution would be to lease a dedicated line however; this option would be a very expensive one and is unnecessary due to new Virtual Private Network (VPN) technologies such as Layer 2 Tunneling Protocol (L2TP). Layer 2 Tunneling Protocol (L2TP) is a VPN technology allows for communication between two LAN segments separated by geographic...

Words: 2057 - Pages: 9

Premium Essay

Nt1310 Unit 3 Assignment 3

...Wireshark Wireshark, a network analysis tool formerly known as Ethereal, collects packets in real time and display them in human-readable format. Wireshark includes filters, color-coding and numerous other features that allows deep analysis of network traffic and scrutinizes specific packets. It is used for networking troubleshooting, Malware analysis and education purposes. NMAP Nmap ("Network Mapper") is a Free Security Scanner for Network Exploration and Hacking. It is utilised to scan a network and collects data about the target network. It reports on open ports, Services running in the host, OS information and packet filters and firewall information. John the Ripper John the Ripper (JTR) is free and fast password cracker. Its main purpose is to detect susceptible UNIX passwords. It is one of the most widespread password...

Words: 541 - Pages: 3

Free Essay

Best Practice Guide for a Ddos Attack

...Running head: Best Practice Guide Best Practice Guide for a DDoS Attack WGU – LOT2 Hacking Task 2 Abstract This paper will accompany a PowerPoint presentation about best practices for preventing a DDoS attack. This will be the best practice guide and will be mentioning and elaborating all of the points in the slideshow. Best Practice Guide for a DDoS Attack It is important to have a plan in place when dealing with a DDoS attack. This guide will serve as the best practice guide for the university. Outlined will be some of the best practices to help prevent a DDoS attack and will be followed by the university. The first thing that the university needs to do is create a response plan and practice the plan over and over. The worst thing that could happen is a DDoS attack starts to occur and nobody knows what to do or what their role is in stopping this attack. A team must be formulated and assignments can be broken down between team members to divide and conquer this attack. It is better to have five different people working on five different tasks or ways to stop the attack instead of five people working on one. The best way to understand the attack is to attack yourself and find the weak spots. Performing a vulnerability assessment on your network will give you a better understanding how your networks functions and where you can find single points of failure. Redundancy is being able to still continue working...

Words: 935 - Pages: 4

Premium Essay

Nt1310 Unit 3

...Detection Systems (IDS) monitors and gathers information through log files by sniffing packets. This information is analyzed for possible intrusion attempts. NIDS uses NIC’s running in promiscuous mode to capture and analyzed raw packet in real time (Pollock, 2014). Snort is a rule base system design to monitor different traffic patterns with a sophisticated detection engine that can analyzed and pinpoint attacks at real-time. Depending on the type of site, a security specialist analyzes can present a lot of traffic or very little traffic. 3. What are the advantages of logging more information to the alerts file? The advantage of logging more information from alert files gives security and network admin more information about possible attacks and weak points on a network. Snort can use third party Log Parser to manage Intrusion detection logs. Two convert snort log files into a text format. Admin can use the following command: output alert csv: alert.csv default (Managing Snort Alerts,). The logs can be customized by the admin. 4. What are the disadvantages of logging more information to the alerts file? More information is great but, if that information is compromised this would leave a network vulnerable to any insider or hacker to sell or used this information for their own gained. For example a honeypot is roaming virtual software agents that generate’s a dummy Route Request (RREQ) packet to lure and trap black hole attackers (Selvakumar, 2013). The idea is for an...

Words: 1545 - Pages: 7

Premium Essay

Penetration Testing

...Using penetration testing to enhance your company's security Based on the fundamental principle that prevention is better than cure, penetration testing (pen-testing) is essentially an information assurance activity to determine if information is appropriately secured. Conducted by penetration testers, sometimes referred to as ‘white hats’ or ethical hackers, these tests use the same tools and techniques as the bad guys (‘black hat hackers’), but do so in a controlled manner with the express permission of the target organization. Vulnerability scans versus pen-testing A common area of confusion is the relationship between vulnerability scanning (automated) and pen-testing (expert-driven manual testing). Both involve a proactive and concerted attempt to identify vulnerabilities that could expose the organization to a potential malevolent attack. Vulnerability scanners are great at identifying ‘low-hanging’ vulnerabilities, such as common configuration mistakes or unpatched systems that offer an easy target for attackers. What they are unable to determine is the context or nature of the asset or data at risk. They are also less able than humans to identify unknown-unknowns (things not already on the risk register, or which haven't been theorized by the organization as potential security issues). Good pen-testing teams, however, do this very well. For instance, pen-testers can give countless examples of engagements where an environment was previously scanned only for vulnerabilities...

Words: 1752 - Pages: 8

Premium Essay

Computer Security

...TITLE: PERSONAL NETWORK SECURITY INTRODUCTION: Computer security is the process of detecting unauthorised use of your computer or PC . As the old saying goes “prevention is better than cure” , going by this we realise that if we learn about the possible loopholes in the security we can prevent it in the first place. But the big question is 'why should i care about my computer security?' . We use computers for everything from banking and investing to shopping and communicating with others through email or chat programs.Although we may not consider our communiction a 'top secret' ,but you dont want others to eavesdrop on you conversations, read your mails, use your computer to attack others system , send forged mails from your computer to others or check the stuff from your computer hard drive. There are many people who whould want to break into you computer system they are generally known as hackers or crackers . More often they do this because they want to launch an attack on some computer system through your computer and other times it is done by some teenage kid who want to showcase his skills and feel proud of himself and maybe even gain some limelight. If your computer is connected to the internet then you dont need some hacker to personally attack your system . There are thousand of computer programs to do this job on the net. Even if you use your internet just to check your e-mails you could still be a huge target for attackers. Is it easy to break into my...

Words: 1142 - Pages: 5

Premium Essay

Lot Task2

...Joseph W Costa LOT2 Task 2 5/24/2013 Best Practices in Prevention of DoS/DDoS Attacks This guide is meant to describe best practices for the detection and prevention of denial of service attacks, such as the event that recently occurred at the university. It was determined that based on current security guidelines and current controls in place, the university was still severely vulnerable from an internal aspect and all identified gaps need to be addressed and resolved. Each control described below will provide a more in depth look at the overall strategy of how a network should be protected but still allow for the functionality that is required to maintain normal operations. Know the Signs of an Attack An essential part of network security is knowing what the characteristics of an attack are, so they can be countered or prevented. When the university suffered an overwhelming internal DDoS attack, it required administrators to reevaluate its security guidelines based on what was known about the attack. As seen at the time of attack, certain characteristics were: Network performance unusually slow Website was unavailable for at least 24 hours Thousands of bogus HTTP packets sent to internal web server Taking these factors into account, it can be safe to say it was an actual attack rather than just legitimate network usage. Now that it is known what such an event would look like, identifying similar attacks in the future will be much easier and may allow...

Words: 1264 - Pages: 6

Premium Essay

Computer Network & Information Security

...damaged, access of personal computers can be gained without permission, viruses and worms can enter creating problems for a user, and our computers may be susceptible to cyber-attacks from hackers. Yet most computer users are new to the technology or do not realize the dangers at hand. This is why users need to learn how to keep their personal computer safe. To achieve a good level of security, there are many important elements that must be taken into account: authentication, access control, data integrity, content protection, etc. Information security can be obtained using methods such as cryptography and network protocols. Computer security is the process of detecting unauthorized use of your computer or PC. As the old saying goes “prevention is better than cure”, according to this we realize that if we learn about the possible loopholes in the security, then we can prevent it from occurring in the first place. But the big question is 'why should I care about my computer security?’. We use computers for everything from banking and investing to shopping and communicating with others through email or chat programs. Although we may not consider our communication a 'top secret', but you don’t want others to eavesdrop on you conversations, read your mails, use your computer to attack others system, send forged mails from your computer to others or check the stuff from your computer hard drive. There are many people who would want to break into your computer system they are generally...

Words: 1454 - Pages: 6

Premium Essay

Week 7 Project Paper

...American Military University All about Network Security: Network Security Means Never Giving an Adversary a Chance. Anthony Portz 4199864 ISSC340 I001 SPR 14 Professor Alidad Jalinous June 16th, 2014 11:55 PM Introduction In this paper I will discuss network security and I will give a detailed description of the area while discussing different technologies that are involved. There are many ways to provide network security and a lot of different aspects to keep in mind. There are a multitude of people who want to attack the internet and everything that it loves. Well luckily there are big security companies like Cisco and Symantec who are there for the user like Tron, and will constantly defend newly discovered loopholes and vulnerabilities. See what global implications network security has and what the future may hold as I discuss the cutting edge technology and applications that new companies are coming out with. What is Network Security? Network security is a terminology that is used to describe any and all actions that are taken to protect and defend a network. Any action that is driven towards network security should be taken to protect the safety, reliability, usability, and the integrity of the network and all of its data. In order to explain network security a little better, I want to define what a network is. A network is defined as a system or grouping of interconnected items or individuals, and as an arrangement of vertical or horizontal lines that...

Words: 3413 - Pages: 14

Premium Essay

Lot2 Task2

...Web site/server for legitimate traffic during the attack. (Schifreen, R. (2006)) This is considered a Consumption of Resources attack using up all the resources of RSS bandwidth. (Specht, S. M., & Lee, R. B. (2004)) These best practices would help prevent and/or reduce the effects of such attacks. Industry best practices to counter DDoS attacks start with documentation that addresses procedures to be followed before, during, and after an attack. (Schifreen, R. (2006)) The establishment of a Security Incident Response Team (SIPT) trained to react to incidents reduces damage and duration of outages. Best practices include; training, network configuration, patch management, access control lists, encryption, intrusion detection, intrusion prevention, and traffic shaping. (Cunningham, B, Dykstra, T, Fuller, E, Gatford, C, Gold, A, Hoagberg, M, Hubbard, A, Little, C, Manzuik, S, Miles, G, Morgan, C, Pfeil, K, Rogers, R, Schack, T, & Snedaker, S, (2007)) Devising a plan that detects problems early requires proper training to recognize and report problems for both end users and Information Technology (IT) staff. IT staff and SIPT members should be trained on proper procedures to diagnose, respond to attacks and forensic incident handling. Collecting forensic data during...

Words: 1240 - Pages: 5

Premium Essay

Network Critque

...Kudler Fine Foods Network One of the considered “best fine food stores” around is the Kudler Fine Foods. However, Kudler is in serious need of a network infrastructure upgrade of their old one. To introduce the latest technologies in data collection, company communication, and information protection while providing the best data speeds and network access are the main goals of the enterprise network. This huge step is significant as this will increase the revenue and will reduce the costs of operation throughout the Kudler Fine Foods stores. Kudler Fine Foods will go back up to technological speed as the network upgrade is completed, while at the same time improving the way they keep track of inventory and sales by using data mining techniques, which will be collected and analyzed in real time. Network Overview The review of the current network used at Kudler Fine Foods was able to determine that the network topology that is being used is the bus topology. The bus network is set-up in such a way that all the network components are connected via CAT5 to the bus or communication line. This configuration is true at sites in the corporation for their workstations, servers, and standalone UPS. A 56k modem is the device that is used by all of the networks communicating to the internet. Although the bus network is very reasonable when it comes to cost, the downfall is that when the backbone goes down, the entire network can encounter an outage that is very difficult to troubleshoot...

Words: 1871 - Pages: 8

Premium Essay

Individual: Indp, Part 2

...Kudler Fine Foods Network Overview NTC/362 - FUNDAMENTALS OF NETWORKING Instructor: ANDREW CARPENTER Individual: INDP, Part 2 Assignment The Kudler Fine Foods is one the best fine food stores around. They have come a long way in such a short amount of time. However, Kudler has out grown the old network infrastructure and is in major need of an enterprise wide upgrade. The strategic goals of the enterprise network are to introduce new technologies in data collection, company communication, and information protection while providing the best data speeds and network access. An upgrade is very important to Kudler Fine Foods and if done correctly it will increase revenue and reduce the cost of operations in all Kudler Fine Food stores. The new network will bring Kudler Fine Foods back up to technological speed and at the same time improve the way they keep track of inventory and sales by using data mining techniques which will be collected and analyzed in real time. After careful review of the Kudler Fine Foods network currently in use, it has been determined the network topology being used at this time is the bus network. The bus network is set-up in such a way that all the network nodes are connected via CAT5 to the bus or communication line. All of the sites in the corporation are using the same configuration of workstations, servers, and standalone ups. All the networks have one way of communicating to the Internet, which is by 56k modems. The...

Words: 2101 - Pages: 9