Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Packet forensics using TCP
Don Parker, Mike Sues

Most of us who work in the security world have at one time or another looked at the raw output of a firewall, IDS, or other type of security device. What that output invariably leads one to is viewing packets directly for an investigation. Doing packet forensics can be a difficult and time consuming endeavour. Due to this fact, many of us prefer to use convenient tools such as Ethereal to help facilitate our analysis. There is a notable problem with this approach, however.

Comments Mode:
Packet forensics using TCP 2005-09-25
Anonymous
nice job guys!

Helped me get some things straight.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1845/6#6
Packet forensics using TCP 2005-10-20
pandian
Packet forensics using TCP 2006-06-02
CMory (1 replies)
Re: Packet forensics using TCP 2006-07-06
Don Parker
Packet forensics using TCP 2006-10-05
Mikkous
Packet forensics using TCP 2006-11-26
Anonymous (1 replies)
Re: Packet forensics using TCP 2006-11-30
Don Parker
Packet forensics using TCP 2007-03-01
Aju Thomas
Packet forensics using TCP 2008-04-08
Anonymous







 

Privacy Statement
Copyright 2007, SecurityFocus