首页> 外文期刊>International Journal of Security and Networks >Network forensics analysis using Wireshark
【24h】

Network forensics analysis using Wireshark

机译:使用Wireshark进行网络取证分析

获取原文
获取原文并翻译 | 示例
           

摘要

The number and types of attacks against networked computer systems have raised the importance of network security. Today, network administrators need to be able to investigate and analyse the network traffic to understand what is happening and to deploy immediate response in case of an identified attack. Wireshark proves to be an effective open source tool in the study of network packets and their behaviour. In this regard, Wireshark can be used in identifying and categorising various types of attack signatures. The purpose of this paper is to demonstrate how Wireshark is applied in network protocol diagnosis and can be used to discover traditional network attacks such as port scanning, covert FTP and IRC channels, ICMP-based attacks, BitTorrent-driven denial service, and etc. In addition, the case studies in this paper illustrate the idea of using Wireshark to identify new attack vectors.
机译:针对网络计算机系统的攻击的数量和类型提高了网络安全性的重要性。如今,网络管理员需要能够调查和分析网络流量,以了解正在发生的事情,并在发现攻击后立即做出响应。在研究网络数据包及其行为时,Wireshark被证明是一种有效的开源工具。在这方面,Wireshark可用于识别和分类各种类型的攻击特征。本文的目的是演示Wireshark如何在网络协议诊断中应用,并可以用来发现传统的网络攻击,例如端口扫描,隐蔽FTP和IRC通道,基于ICMP的攻击,BitTorrent驱动的拒绝服务等。此外,本文中的案例研究说明了使用Wireshark识别新的攻击媒介的想法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号