IF YOU ARE NOT GOOD IN IT,DO NOT HANDSHAKE-PRACTICE EXAMINING TRAFFIC WITH A PROTOCOL ANALYZER
Laboratory 2 The purpose of this lab is to practice examining traffic using a protocol analyzer and recognize a SYN attack. The SYN flood attack is one of the common Denial of Service (DoS) attacks in the Internet. In the SYN flood attack, an attacker sends a large number of SYN packets to the server, ignores SYN/ACK replies and never sends the expected ACK packet. Basically, the attacker overwhelms the server with many half-established connections and exhausts the server resources, and hence the attack is known as a DoS attack. The tool you will be using is known as Wireshark, a well-known open source packet analyzer. The exercise will demonstrate that recognizing an attack requires sophisticated tools (such as Wireshark) and knowledge of the domain (TCP/IP network). Assignment: 1. Obtain a trace file of the TCP handshake process. Download the attached files: "tcpshake.cap," "tcpshake.prn" (TCP: Handshake Process) and "tcp-syn-attack.cap," "tcp-syn-attack.prn," (TCP: TCP SYN Attack). The .prn file is a text file, and you can read it with Notepad or Wordpad. It contains a formatted "report" with information on each packet. The .cap file is in the proprietary Sniffer format. Opening this file produces a graphic representation of the same information. You can read .cap files with Wireshark/Ethereal, a public domain analyzer. 2. Obtain Wireshark
If you use a packet driver, Wireshark can both capture packets and read trace files of packets that have already been captured. However, the packet driver must access parts of your operating system that some students may not have access to. That is the reason why this is not a packet capturing exercise. However, you should learn to capture packets yourself if you can. The packet driver you will need is winpcap. It is available at http://www.winpcap.org/install/. However, you do not need winpcap for the exercise you are going to do now. 3. Read the tcpshake.cap trace file. Become familiar with Wireshark's interface.
4. Read the tcp-syn-attack.cap file and answer the following 10 questions:
Post your answer to the assignment folder under LAB2 (due date: 11/13).
| |
10 years ago
5
Purchase the answer to view it

- wireshark_answers.docx
Purchase the answer to view it

- laboratory_2.docx
Purchase the answer to view it

- INFA_620_Laboratory_2.docx
- Research the population demographics in the area or state where you live. Use the following guidelines for your research: Look up government...
- Assuming that you are the clinical content manager and lead all reporting efforts, what approach would you take to address the reporting problem?
- Prof. Frank...
- Wordwhiz only
- the Silk Roads in the Classic Period (600 BCE-600 CE)
- One month a shop ordered 95 total units from 3 different suppliers
- BUS 335 Week 4 Assignment 1 Staffing Organziations Part 1-2
- Finance
- HRM 324 Total Compensation
- FIN 370 Week 4 My Finance Lab


