TAILIEUCHUNG - Traffic Analysis Techniques 1

Traffic Analysis is a set of techniques for arranging and visualizing data so that patterns and relations can be identified, tagged or tracked. This course serves as a primer for taking logfiles of virtually any format, organizing the data and performing the analysis. | Traffic Analysis Techniques 1 Traffic Analysis is a set of techniques for arranging and visualizing data so that patterns and relations can be identified tagged or tracked. This course serves as a primer for taking logfiles of virtually any format organizing the data and performing the analysis. IDIC - SANS GIAC LevelTwo 2000 2001 1 This section of the course will concentrate on externals the fields in the packet header more than the content. The purpose of this section is to teach the analysis of packets based on their behavior and the fields. I hope that you find the material in this section to be something that you can use as you analyze network traffic. 1 Common External Dimensions Date time To From Service Service port numbers Sequence numbers Four W s Who What Where When Extra credit Why IDIC - SANS GIAC LevelTwo 2000 2001 2 When we talk about columns and typing we are approaching the subject of highly dimensional data. Consider the date field a dimension time another and so forth. By highly dimensional we mean lots of columns . Just about any field in the headers can be used to create another dimension. Most of the time many fields will contain normal non-descript values and will not add anything to our focus if we are trying to analyze traffic. However there are times when a crafted unique value in an inherently uninteresting field may provide some kind of signature. For instance sequence numbers when normally generated are not of much interest to us as analysts. However if we spy a static sequence number or even a repeated acknowledgement number from what appears to be a reply from a static sequence number we may begin to see a pattern of some sort which will ultimately assist in the analysis. The more clues that you can find in the data the more help you have in possibly explaining why you are seeing what you are seeing. 2 From To Service Are Primary Events of Interest Where do our hits come from Who What are they targeting Can we find evidence of crafted

TỪ KHÓA LIÊN QUAN
TAILIEUCHUNG - Chia sẻ tài liệu không giới hạn
Địa chỉ : 444 Hoang Hoa Tham, Hanoi, Viet Nam
Website : tailieuchung.com
Email : tailieuchung20@gmail.com
Tailieuchung.com là thư viện tài liệu trực tuyến, nơi chia sẽ trao đổi hàng triệu tài liệu như luận văn đồ án, sách, giáo trình, đề thi.
Chúng tôi không chịu trách nhiệm liên quan đến các vấn đề bản quyền nội dung tài liệu được thành viên tự nguyện đăng tải lên, nếu phát hiện thấy tài liệu xấu hoặc tài liệu có bản quyền xin hãy email cho chúng tôi.
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.