J
Jaisol
I`m not sure if interpretation what I do about malicious traffic
(external/internal) is correct or maybe this concept is very subjective or
complex.
Anyway, I understand for malicious traffic like all traffic
(external/internal) able to go against good use of resources afecting
performance, services, ..., between one or more machines and can be intended
(e.g. virus/trojans) or unintended (e.g. bugs, misconfiguration, p2p).
I've read about network analyzers/monitoring like sniffers and MS Network
Monitor/Ethereal tools between others like ISA logs BUT once inside of them
I can`t identify malicious traffic.
I have spoke with experts in matter and always they recommend to use
sniffers and similar tools but to the question "how can I identify malicious
traffic once inside of them utilities?" they respond vaguely and evasively.
Have this traffic some clue (protocol, port, frame, size, ...) that help to
identify it?
For that I really appreciate any kind of help can guide me to identify
malicious traffic (internal) in LAN environment.
Of course any commenst/suggestions/recommendations will be appreciated.
THANKS!
(external/internal) is correct or maybe this concept is very subjective or
complex.
Anyway, I understand for malicious traffic like all traffic
(external/internal) able to go against good use of resources afecting
performance, services, ..., between one or more machines and can be intended
(e.g. virus/trojans) or unintended (e.g. bugs, misconfiguration, p2p).
I've read about network analyzers/monitoring like sniffers and MS Network
Monitor/Ethereal tools between others like ISA logs BUT once inside of them
I can`t identify malicious traffic.
I have spoke with experts in matter and always they recommend to use
sniffers and similar tools but to the question "how can I identify malicious
traffic once inside of them utilities?" they respond vaguely and evasively.
Have this traffic some clue (protocol, port, frame, size, ...) that help to
identify it?
For that I really appreciate any kind of help can guide me to identify
malicious traffic (internal) in LAN environment.
Of course any commenst/suggestions/recommendations will be appreciated.
THANKS!