Snort 2.0 Intrusion Detection

Experimental Preprocessors

The preprocessors listed in the following sections are all experimental or not-yet-Enterprise-grade. They're either under development, not yet finished or generally experimental; consequently, they're generally not enabled by default. However, you might want to try them out if you're either looking for the particular functionality that they offer, or you're interested in helping to develop or test new Snort code. For example, you might want to detect ARP spoofing attacks, perhaps to see if any attackers are performing active-sniffing attacks against your switched networks. This might lead you to the arpspoof detection preprocessor, described next.

arpspoof

The arpspoof preprocessor detects Address Resolution Protocol (ARP) spoofing attacks, like those available via dsniff's arpspoof (http://naughty.monkey.org/~dugsong/dsniff/). An attacker uses ARP spoofing on a local network to trick hosts into sending him traffic intended for another host. A host that wants to send an IP packet to another host on the same LAN doesn't generally just send the packet on the LAN it has to know the physical hardware, or Media Access Control (MAC), address of the destination host. This address looks something like AA:BB:CC:DD:11:22, as it is a six-octet number. To learn the MAC address that it needs, it broadcasts an ARP request, along the lines of "who has IP address 10.0.0.1? Tell AA:BB:CC:DD:11:22?" The destination host responds with its own MAC address, which the sender then caches and uses for all traffic it sends to that host for a set period of time, called the cache entry Time-To-Live (TTL). In an...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Packet Generators
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.