首页> 外文OA文献 >An evaluation of network based sniffer detection; Sentinel
【2h】

An evaluation of network based sniffer detection; Sentinel

机译:基于网络的嗅探器检测评估;哨兵

摘要

Today, tools for sniffer detection have become a standard part of the security toolkit, used to protect computing assets from hostile attacks. The Open Source Network-based sniffer detection tool Sentinel, is commonly found in various security toolkits, and widely used by administrators. Under normal circumstances, Sentinel detects common non-standalone packet sniffers quite reliably. But, its reliability is still questionable. This due to the fact, that since the introduction of Network-based non-standalone sniffer detection, various counter methods have been suggested, to make sniffers impossible to detect. This research effort tries to evaluate the reliability of Network-based sniffer detection, regarding the various counter methods proposed. The research was conducted by standardized experiments conducted with Sentinel, and a survey examination among system administrators. The major findings of this research are that; Network-based sniffer detection, as it is generally conducted today, can not be considered very reliable. Therefore, sniffers should mainly be fought using prevention not detection.
机译:如今,嗅探器检测工具已成为安全工具包的标准组成部分,用于保护计算资产免受恶意攻击。基于开源网络的嗅探器检测工具Sentinel通常在各种安全工具包中找到,并被管理员广泛使用。在正常情况下,Sentinel非常可靠地检测到常见的非独立数据包嗅探器。但是,其可靠性仍然值得怀疑。这是由于以下事实:自从引入基于网络的非独立嗅探器检测以来,已提出了各种计数器方法,以使嗅探器无法检测。这项研究工作试图针对提出的各种对策来评估基于网络的嗅探器检测的可靠性。该研究是通过与Sentinel进行的标准化实验以及系统管理员之间的调查检查来进行的。这项研究的主要发现是:如今,基于网络的嗅探器检测通常被认为是非常可靠的。因此,嗅探器应该主要使用预防而不是检测来对抗。

著录项

  • 作者

    Susid Daniel;

  • 作者单位
  • 年度 2004
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号