Assume a network administrator suspects a host on the network has malware and is communicating with an unknown website. How can performing a packet sniffer and filtering by DNS entries enable the security team to locate the infected computer?
Added by Kevin C.
Your feedback will help us improve your experience
Chandra Jain and 66 other AP CS educators are ready to help you.
Ask a new question
Labs
Want to see this concept in action?
Explore this concept interactively to see how it behaves as you change inputs.
Key Concepts
Recommended Videos
A company is concerned with traffic that flows through the network. There is a concern that there may be malware that exists that is not being blocked or eradicated by antivirus. What technology can be put in place to detect potential malware traffic on the network?
Chandra J.
Hijack a DNS session using dnsspoof. Capture the packets between your victim. Submit a short explanation of why or why not the program works as well as ettercap, referencing the packet capture to describe any problems.
Akash M.
Case Project 13-2: Detecting Hackers in the Alexander Rocco Network You receive a frantic call from the system administrator of the Alexander Rocco network, JW Tabacchi. He tells you he has identified several intrusion attempts from sources over the Internet. You're not sure if the hackers have gained access to the internal network. First, based on the tools described in this chapter and some of the techniques you've learned in this book, write a TWO-PAGE report about the things you might look for to identify an attacker or a compromised host on your network. Second, make some recommendations on how you might instrument the network with network protection systems to better detect and prevent compromises in the future.
Recommended Textbooks
Computer Science and Information Technology
Introduction to Programming Using Python
Computer Science - An Overview
Transcript
Watch the video solution with this free unlock.
EMAIL
PASSWORD