19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 8-9:<br />

OmniPeek<br />

can help<br />

uncover<br />

someone<br />

running an<br />

illicit system,<br />

such<br />

as an FTP<br />

server.<br />

Chapter 8: Network Infrastructure<br />

✓ When network traffic doesn’t look right in a network analyzer, it probably<br />

isn’t. It’s better to be safe than sorry.<br />

Run a baseline when your network is working normally. When you<br />

have a baseline, you can see any obvious abnormalities when an attack<br />

occurs.<br />

One thing I like to check for is the top talkers (network hosts sending/receiving<br />

the most traffic) on the network. If someone is doing something malicious<br />

on the network, such as hosting an FTP server or running Internet file-sharing<br />

software, using a network analyzer is often the only way you’ll find out about<br />

it. A network analyzer is also a good tool for detecting systems infected with<br />

malware, such as a virus or Trojan horse. Figure 8-9 shows what it looks like<br />

to have a suspect protocol or application running on your network.<br />

Looking at your network statistics, such as bytes per second, network utilization,<br />

and inbound/outbound packet counts, is also a good way to determine<br />

whether something fishy is going on. Figure 8-10 contains network statistics<br />

as seen through the powerful CommView network analyzer.<br />

TamoSoft — the maker of CommView — has another product called<br />

NetResident (www.tamos.com/products/netresident) that can track<br />

the usage of well-known protocols, such as HTTP, e-mail, FTP, and VoIP. As<br />

shown in Figure 8-11, you can use NetResident to monitor web sessions and<br />

play them back.<br />

143

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!