80 likes | 226 Views
ORGANISATIONAL SYSTEMS SECURITY Unit 15 Lecture 2. NETWORK ANALYSIS SOFTWARE. Learning Objectives. EXAMPLES OF NETWORK ANALYSIS SOFTWARE Ettercap Wireshark (Ethereal) NMap Angry IP Scanner. Ettercap (Primary ARP Poisoning Tool). Can intercept traffic on a network segment
E N D
ORGANISATIONAL SYSTEMS SECURITYUnit 15 Lecture 2 NETWORK ANALYSIS SOFTWARE BTEC NAT Unit 15 - Organisational Systems Security
Learning Objectives EXAMPLES OF NETWORK ANALYSIS SOFTWARE • Ettercap • Wireshark (Ethereal) • NMap • Angry IP Scanner BTEC NAT Unit 15 - Organisational Systems Security
Ettercap(Primary ARP Poisoning Tool) • Can intercept traffic on a network segment • Can capture passwords & conduct Man in the Middle attacks • Filters data packets by IP addresses or MAC addresses • ARP poisoning (MIM) between victims & hosts • OS fingerprinting of victims & Killing of connections • Passive scanning of host’s information • Find other poisoners on the network BTEC NAT Unit 15 - Organisational Systems Security
WIRESHARK (Ethereal) • Free packet sniffer application • Protocol scanner looking at data packets • Used in the detection of Keyloggers • See all traffic passed over a network or outgoing traffic from a computer • Network Troubleshooting Analysis BTEC NAT Unit 15 - Organisational Systems Security
NMAP • Network Security Scanner • Deep probe scanner to reveal information about a device • Creates a map of the network – computers & services • Can discover passive services not advertised • Port Scanning & O/S detection of network devices • Audit the security of a computer or network BTEC NAT Unit 15 - Organisational Systems Security
ANGRY IP SCANNER • Fast & visual scanner looking at a large range of IP addresses • Can check TCP ports during scan • Can also display NetBios and device information BTEC NAT Unit 15 - Organisational Systems Security
Internal & External Threats BTEC NAT Unit 15 - Organisational Systems Security
Unauthorised Access – Internal Threats Scanners • Establish what methods may be used to attack a system • Scan a range of IP addresses – active or passive (can map to a domain name) • Check TCP ports – open & closed Deep Probe – Useful information about any device Wireless Systems scanner – establish access points within range (Retina Network Security Scanner) BTEC NAT Unit 15 - Organisational Systems Security