Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Packet forensics using TCP
Don Parker, Mike Sues

Most of us who work in the security world have at one time or another looked at the raw output of a firewall, IDS, or other type of security device. What that output invariably leads one to is viewing packets directly for an investigation. Doing packet forensics can be a difficult and time consuming endeavour. Due to this fact, many of us prefer to use convenient tools such as Ethereal to help facilitate our analysis. There is a notable problem with this approach, however.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 





 

Privacy Statement
Copyright 2009, SecurityFocus