Security awareness: A lesson from Tcpdump and Ethereal
Ethernet has survived for several decades as essential media for LAN technology because of its relative inexpensive and reasonably fast. Shared Ethernet uses broadcast technology where CSMA/CD acts as medium access control. CSMA/CD deploys principle of media sharing and the drawback is promiscuous...
Main Authors: | , , |
---|---|
Format: | Conference or Workshop Item |
Language: | English |
Published: |
2005
|
Subjects: | |
Online Access: | http://eprints.utm.my/5608/1/Foad2005_SecurityAwarenessLessonTcpdumpEthereal.pdf |
_version_ | 1825909767185367040 |
---|---|
author | Rohani, Mohd. Fo’ad Maarof, Mohd. Aizaini Selamat, Ali |
author_facet | Rohani, Mohd. Fo’ad Maarof, Mohd. Aizaini Selamat, Ali |
author_sort | Rohani, Mohd. Fo’ad |
collection | ePrints |
description | Ethernet has survived for several decades as essential media for LAN technology because of its relative inexpensive and reasonably fast. Shared Ethernet uses broadcast technology where CSMA/CD acts as medium access control. CSMA/CD deploys principle of media sharing and the drawback is promiscuous mode, whereby network interface device could intercept all packet frames that traveling on the wire. This has a significant impact on the security of Internet application. HTTP, FTP, E-MAIL and TELNET are daily applications, which offer secure transaction or unsecured transaction. However, users do not aware of the security provided by the services. They usually use unsecured transaction because of simplicity or unaware of security awareness. This behavior is vulnerable to packet-sniffing tools, such as sniffit, tcpdump and ethereal. These tools could intercept the traveling packet and extract sensitive information, such as user login and password or unencrypted data payload. This paper explores network security awareness from the perspective of packet-sniffing tools over unsecured application. The study uses tcpdump and ethereal, which are two of the most popular packet-sniffing tools. From the experiment, it is shown that vital information, such as login and password, could be compromised easily from the packet if users do not consider security awareness seriously. |
first_indexed | 2024-03-05T18:07:04Z |
format | Conference or Workshop Item |
id | utm.eprints-5608 |
institution | Universiti Teknologi Malaysia - ePrints |
language | English |
last_indexed | 2024-03-05T18:07:04Z |
publishDate | 2005 |
record_format | dspace |
spelling | utm.eprints-56082017-08-30T07:38:16Z http://eprints.utm.my/5608/ Security awareness: A lesson from Tcpdump and Ethereal Rohani, Mohd. Fo’ad Maarof, Mohd. Aizaini Selamat, Ali QA75 Electronic computers. Computer science Ethernet has survived for several decades as essential media for LAN technology because of its relative inexpensive and reasonably fast. Shared Ethernet uses broadcast technology where CSMA/CD acts as medium access control. CSMA/CD deploys principle of media sharing and the drawback is promiscuous mode, whereby network interface device could intercept all packet frames that traveling on the wire. This has a significant impact on the security of Internet application. HTTP, FTP, E-MAIL and TELNET are daily applications, which offer secure transaction or unsecured transaction. However, users do not aware of the security provided by the services. They usually use unsecured transaction because of simplicity or unaware of security awareness. This behavior is vulnerable to packet-sniffing tools, such as sniffit, tcpdump and ethereal. These tools could intercept the traveling packet and extract sensitive information, such as user login and password or unencrypted data payload. This paper explores network security awareness from the perspective of packet-sniffing tools over unsecured application. The study uses tcpdump and ethereal, which are two of the most popular packet-sniffing tools. From the experiment, it is shown that vital information, such as login and password, could be compromised easily from the packet if users do not consider security awareness seriously. 2005-05-17 Conference or Workshop Item PeerReviewed application/pdf en http://eprints.utm.my/5608/1/Foad2005_SecurityAwarenessLessonTcpdumpEthereal.pdf Rohani, Mohd. Fo’ad and Maarof, Mohd. Aizaini and Selamat, Ali (2005) Security awareness: A lesson from Tcpdump and Ethereal. In: Proceedings of the Postgraduate Annual Research Seminar 2005 (PARS 05), 17-18 May 2005, FSKSM, UTM. |
spellingShingle | QA75 Electronic computers. Computer science Rohani, Mohd. Fo’ad Maarof, Mohd. Aizaini Selamat, Ali Security awareness: A lesson from Tcpdump and Ethereal |
title | Security awareness: A lesson from Tcpdump and Ethereal |
title_full | Security awareness: A lesson from Tcpdump and Ethereal |
title_fullStr | Security awareness: A lesson from Tcpdump and Ethereal |
title_full_unstemmed | Security awareness: A lesson from Tcpdump and Ethereal |
title_short | Security awareness: A lesson from Tcpdump and Ethereal |
title_sort | security awareness a lesson from tcpdump and ethereal |
topic | QA75 Electronic computers. Computer science |
url | http://eprints.utm.my/5608/1/Foad2005_SecurityAwarenessLessonTcpdumpEthereal.pdf |
work_keys_str_mv | AT rohanimohdfoad securityawarenessalessonfromtcpdumpandethereal AT maarofmohdaizaini securityawarenessalessonfromtcpdumpandethereal AT selamatali securityawarenessalessonfromtcpdumpandethereal |