Computer and Network Security

Table of Contents

Lecture 2: Network security 1

Recap: computer networks has several layers

Network layering

Local Area Network attacks

The attacker is present directly on the local network.

Sniffing

Attacker sets network interface to promiscuous mode => can access all traffic on the segment.

Why?

Tools

Detecting sniffers:

If we want to sniff: TCPDump (analyses traffic on network segment, can use expressions to filter packets)

But switched ethernet doesn’t allow direct sniffing… solutions:

Spoofing

ARP spoofing with forwarding

IP spoofing (local network)

Spoofing remotely

UDP spoofing

Hijacking

Steps: