Sniffing Detection within the Network

Krzysztof Cabaj, Marcin Gregorczyk, Wojciech Mazurczyk, P. Nowakowski, Piotr Żórawski · 2019

Sniffing is a crucial part of the network attack where an intruder tries to gather as much information as possible on the devices, protocols and applications residing within the targeted network in order to discover their vulnerabilities. It is typically performed using dedicated software called sniffers and it is based on passively analyzing the traffic exchanged within the network. Due to its passive nature such malicious actions are quite hard to be discovered. That is why, in this paper we first revisit existing approaches and tools known from the state-of-the-art. Then we introduce a novel detection method which is able to identify suspicious machine using specially crafted network traffic and based on its reaction is able to infer whether sniffer is running or not.

Read the paper · More papers on PaperTik