how they were infected, what they were infected with, and who attacked them, a corporation with a hacked system would conduct a packet analysis.
The Packet Analysis plugin architecture handles parsing of packet headers at layers below Zeek's existing Session analysis.
Packet Analysis can be crucial in identifying multiple stages of the Kill Chain.
- By identifying these stages, it becomes easier to defend against an attacker
at different stages of the Kill Chain.
Control information and user data, usually referred to as the payload, make up a packet. Data for delivering the payload, including as source and destination network addresses, error
detection codes, and sequencing information, are provided by control information.
Consider it similar to a text or email. Sender, Receiver, and Contents are included.
DNS
- Uses UDP instead of TCP to
transport.
- Translates more readily memorized
domain names to the numerical IP.
- For example: When you go to the
website google.com, it navigates to
the IP address 172.217.164.174.
TCP
- Threeway Handshake: Used by
TCP in order to establish a
connection between the Host and
Destination. Consists of 3 TCP
Flags:
- SYN
- ACK
- SYN & ACK
- Transport level of OSI
The Packet Analysis plugin architecture handles parsing of packet headers at layers below Zeek's existing Session analysis.


Comments
Post a Comment