DocumentCode :
1951008
Title :
Network Traffic Analysis and Intrusion Detection Using Packet Sniffer
Author :
Qadeer, Mohammed Abdul ; Zahid, Mohammad ; Iqbal, Arshad ; Siddiqui, MisbahurRahman
Author_Institution :
Dept. of Comput. Eng., Aligarh Muslim Univ., Aligarh, India
fYear :
2010
fDate :
26-28 Feb. 2010
Firstpage :
313
Lastpage :
317
Abstract :
Computer software that can intercept and log traffic passing over a digital network or part of a network is better known as packet sniffer. The sniffer captures these packets by setting the NIC card in the promiscuous mode and eventually decodes them. The decoded information can be used in any way depending upon the intention of the person concerned who decodes the data (i.e. malicious or beneficial purpose). Depending on the network structure one can sniff all or just parts of the traffic from a single machine within the network. However, there are some methods to avoid traffic narrowing by switches to gain access to traffic from other systems on the network. This paper focuses on the basics of packet sniffer and its working, development of the tool on Linux platform and its use for Intrusion Detection. It also discusses ways to detect the presence of such software on the network and to handle them in an efficient way. Focus has also been laid to analyze the bottleneck scenario arising in the network, using this self developed packet sniffer. Before the development of this indigenous software, minute observation has been made on the working behavior of already existing sniffer software such as wireshark (formerly known as ethereal), tcpdump, and snort, which serve as the base for the development of our sniffer software. For the capture of the packets, a library known as libpcap has been used. The development of such software gives a chance to the developer to incorporate the additional features that are not in the existing one.
Keywords :
Linux; computer network security; network analysers; telecommunication traffic; Linux platform; NIC card; computer software; digital network; indigenous software; intrusion detection; log traffic passing; network structure; network traffic analysis; packet sniffer; working behavior; Band pass filters; Computer networks; Decoding; Intrusion detection; Kernel; Libraries; Monitoring; Network interfaces; Operating systems; Telecommunication traffic; Berkeley Packet Filter; NIC; Network analyzer; Packet capture; intrusion detection; libpcap; network monitoring; packet sniffer; promiscuous mode; traffic analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communication Software and Networks, 2010. ICCSN '10. Second International Conference on
Conference_Location :
Singapore
Print_ISBN :
978-1-4244-5726-7
Electronic_ISBN :
978-1-4244-5727-4
Type :
conf
DOI :
10.1109/ICCSN.2010.104
Filename :
5437681
Link To Document :
بازگشت