Networking Forums

Networking Forums > Computer Networking > Windows Networking > About malicious traffic and how to identify it...

Reply
Thread Tools Display Modes

About malicious traffic and how to identify it...

 
 
Jaisol
Guest
Posts: n/a

 
      02-15-2006, 08:06 PM
I`m not sure if interpretation what I do about malicious traffic
(external/internal) is correct or maybe this concept is very subjective or
complex.

Anyway, I understand for malicious traffic like all traffic
(external/internal) able to go against good use of resources afecting
performance, services, ..., between one or more machines and can be intended
(e.g. virus/trojans) or unintended (e.g. bugs, misconfiguration, p2p).

I've read about network analyzers/monitoring like sniffers and MS Network
Monitor/Ethereal tools between others like ISA logs BUT once inside of them
I can`t identify malicious traffic.
I have spoke with experts in matter and always they recommend to use
sniffers and similar tools but to the question "how can I identify malicious
traffic once inside of them utilities?" they respond vaguely and evasively.

Have this traffic some clue (protocol, port, frame, size, ...) that help to
identify it?

For that I really appreciate any kind of help can guide me to identify
malicious traffic (internal) in LAN environment.

Of course any commenst/suggestions/recommendations will be appreciated.

THANKS!

 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a

 
      02-15-2006, 09:39 PM
From: "Jaisol" <(E-Mail Removed)>

| I`m not sure if interpretation what I do about malicious traffic
| (external/internal) is correct or maybe this concept is very subjective or
| complex.
|
| Anyway, I understand for malicious traffic like all traffic
| (external/internal) able to go against good use of resources afecting
| performance, services, ..., between one or more machines and can be intended
| (e.g. virus/trojans) or unintended (e.g. bugs, misconfiguration, p2p).
|
| I've read about network analyzers/monitoring like sniffers and MS Network
| Monitor/Ethereal tools between others like ISA logs BUT once inside of them
| I can`t identify malicious traffic.
| I have spoke with experts in matter and always they recommend to use
| sniffers and similar tools but to the question "how can I identify malicious
| traffic once inside of them utilities?" they respond vaguely and evasively.
|
| Have this traffic some clue (protocol, port, frame, size, ...) that help to
| identify it?
|
| For that I really appreciate any kind of help can guide me to identify
| malicious traffic (internal) in LAN environment.
|
| Of course any commenst/suggestions/recommendations will be appreciated.
|
| THANKS!

You need to learn how to post !
This Cross-Posted, Multi-Posted message has gone to /* TOO MANY */ News Groups.

A few security related News Groups was all that was needed. Not ISA, OS and others !

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
Jaisol
Guest
Posts: n/a

 
      02-15-2006, 10:37 PM
> You need to learn how to post !
> This Cross-Posted, Multi-Posted message has gone to /* TOO MANY */ News

Groups.

I`m sorry for that.

> A few security related News Groups was all that was needed. Not ISA, OS

and others !

Thanks for share your knowledgment.

 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a

 
      02-15-2006, 11:54 PM
From: "Jaisol" <(E-Mail Removed)>

>> You need to learn how to post !
>> This Cross-Posted, Multi-Posted message has gone to /* TOO MANY */ News

| Groups.
|
| I`m sorry for that.
|
>> A few security related News Groups was all that was needed. Not ISA, OS

| and others !
|
| Thanks for share your knowledgment.

If you had posted in the RIGHT places and no all over the place, I would have provided
information on malicious TCP/IP traffic.

Therefore, you just got feedback.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
Jaisol
Guest
Posts: n/a

 
      02-16-2006, 03:11 PM
> If you had posted in the RIGHT places and no all over the place, I would
> have provided
> information on malicious TCP/IP traffic.
> Therefore, you just got feedback.


As you can saw I got good feedbacks because many people want share
knowledgement and this attitude confirm great value of newsgroups prevailing
over others attitudes like judge people who do cross-posting by error.

Once again I'm sorry for cross-posting.

 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a

 
      02-16-2006, 06:25 PM
From: "Jaisol" <(E-Mail Removed)>

>> If you had posted in the RIGHT places and no all over the place, I would
>> have provided
>> information on malicious TCP/IP traffic.
>> Therefore, you just got feedback.

|
| As you can saw I got good feedbacks because many people want share
| knowledgement and this attitude confirm great value of newsgroups prevailing
| over others attitudes like judge people who do cross-posting by error.
|
| Once again I'm sorry for cross-posting.

There is nothing wrong with Cross-Posting. Cross-posting is preferred over Multi-Posteing.
The problem was the sheer number of groups this was Cross-Posted and Multi-Posted to. Only
post On Topic to a given News Group and if you you want to cover a few News Groups,
Cross-Post the subject matter to relevant, On Topic News Groups.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
cannot identify network tom healy Wireless Networks 2 10-30-2007 02:50 AM
Need to identify traffic. Doug Laidlaw Linux Networking 3 11-30-2004 05:02 AM
Problem with Malicious calls + broadband mike Broadband 11 05-13-2004 11:23 AM
How to identify a client if the IP or the MAC is known Dave Niemeyer Windows Networking 2 12-11-2003 02:07 PM
Helpctr.exe file - "Malicious Script Detected" by Antivirus Tequila-4-ME Windows Networking 1 07-31-2003 01:06 AM



1 2 3 4 5 6 7 8 9 10 11