Raul Siles

Network traffic / Tráfico de red

Whitepapers Tools Web

This Web page does not contain information about the traffic in your city but the traffic crossing your communication networks, how to analyze it, inspect it to detect its anomalies, and how to play with it and its security. As you probably supposse, it is mainly a TCP/IP oriented resource.

Esta página Web no contiene información sobre el tráfico en tu ciudad, sino sobre el tráfico que atraviesa tus redes de comunicaciones, como analizarlo, inspeccionarlo para detectar anomalías, y cómo jugar con él y con su seguridad. Como puedes suponer está orientado principalmente a TCP/IP.

Whitepapers / Artículos
ICMP Usage In ScanningOfir ArkinJuly 2001
UDP Backoff Pattern Fingerprinting (IPSec - ISAKMP)Roy HillsJanuary 2003
PSK Cracking using IKE Aggressive ModeM. Thumann, E. Rey
TCP/IP Skills Required for Security AnalystsDon ParkerMay 17, 2004
TCP/IP Skills Required for Security Analysts (Part 2)Don ParkerJune 9, 2004
Detecting Worms and Abnormal Activities with NetFlow, Part 1Yiming GongAugust 2004
Detecting Worms and Abnormal Activities with NetFlow, Part 2Yiming GongSeptember 2004
Software Firewalls versus Wormhole TunnelsB. Rudis, P. KostenbaderMay 2005
Introduction to IPAuditPaul AsadoorianJuly 2005

Tools / Herramientas
netcatHobbitNetwork cat for Unix, using TCP or UDP protocol (Windows)
CryptCatFarm9.comnetcat enhanced with twofish encryption (Windows, BSD & Linux)
SDBCycomShadowinteger's Backdoor: a netcat clone (portable & strong encryption)
Project Lokidaemon9, alhambraICMP tunneling: description & implementation
redirSam CreaseyLinux TCP port redirector
nstx Florian HeinzThe Nameserver Transfer Protocol: DNS tunneling

Analysis
EtherealGerald CombsMulti-platform graphical protocol analyzer
TcpDumpV. Jacobson, C. Leres, S. McCanneSniffer: dump traffic on a network (WinDump)
ngrepJordan RitterNetwork grep
SnortMarty RoeschThe open-source network intrussión detection systems (NIDS)
tcpflowJeremy ElsonA TCP Flow Recorder
tcpstatPaul HermanReports certain network interface statistics (like vmstat for system)
EtherApeJuan ToledoGraphical network monitor for Unix modeled after etherman
ChaosreaderBrendan GreggTrace TCP/UDP/... sessions and fetch application data from tcpdump logs
NdiffJames LevineCompares two nmap scans and outputs the differences
NWatchJames LevineSniffer and passive port scanner

Injection
Hping(2)Antirez (S. Sanfilippo)Command-line oriented TCP/IP packet assembler/analyzer
TcpreplayAaron TurnerPcap editing and replay tools for *NIX
NemesisMark Grimes, M. SchiffmanCommand-line network packet injection utility for Unix and Windows
PackITDarren BoundsPacket toolkit is a network auditing tool: network injection and capture
ISICMike FrantzenIP Stack Integrity Checker
SendIPMike RickettsCommandline tool to allow sending arbitrary IP packets
FirewalkM. Schiffman, D. GoldsmithActive reconnaissance network tool to analyze IP forwarding devices
AntMarek WardzinskiGraphical tool for building and injectionf network frames
ScapyPhil BiondiInteractive packet manipulation tool, packet generator...

Libraries
(Lib)PCAPV. Jacobson, C. Leres, S. McCannePacket Capture library (WinPCAP)
(Lib)NETMike D. SchiffmanPacket (network) Construction library
(Lib)NIDSRafal WojtczukNIDS library: IP defrag, TCP reassembly and TCP port scan detection
(Lib)radiateM. Schiffman, T. Newsham802.11b frame assembly/injection library
(Lib)sfS. Bracken, M. SchiffmanIP stack fingerprinting library
(Lib)ipg (ipgeo)Mike D. SchiffmanLibrary for the IP2LOCATION database:geo-targeting of IP addresses
LibdnetDug SongProvides a simplified, portable interface to several low-level networking routines

OS & Service identification
NmapFyodorActive OS fingerprinting (nmap -O) and version scanning (nmap -sV)
THC-Amapvan Hauser (The Hackers Choice)Active application protocol detection
PADSMatt SheltonPassive network signature-based detector
Xprobe(2)Ofir Arkin, Fyodor YarochkinActive OS fingerprinting tools based on the ICMP protocol
ISNproberTom VandepoelSamples TCP Initial Sequence Numbers to determine TCP/IP stack matching

Firewalling
iptables/netfilterNetfilter Core TeamNetwork filtering, NAT and packet mangling framework inside the Linux kernel
ShorewallTom EastepHigh-level tool for configuring Netfilter
FireHOLCosta TsaousisThe iptables stateful packet filtering firewall builder
GuardDogSimon EdwardsA firewall configuration utility for Linux systems
Easy Firewall GeneratorScott MorizotPHP Web application that generates an iptables firewall script

IPSec
ike-scanNTA MonitorVPN Discovery and Fingerprinting tool
IKECrackAnton T. RagerBruteforce crack for IPSec authentication

Web
IEEE OUI assignmentsMAC vendor codes (OUIs)
IANA MatrixIANA Matrix for Protocol Parameter Assignment/Registration Procedures
IANA Ether typesList of Ethernet types, MAC vendor codes, unicast & multicast
IANA Multicast addressesList of Internet multicast addresses assignments
IANA ProtocolsList of protocols numbers
IANA ARP parametersList of ARP types and codes
IANA ICMP parametersList of ICMP types and corresponding codes
IANA IP parametersList of IP options and TOS parameters
IANA TCP parametersList of TCP options and checksums
IANA TCP header flagsList of TCP header flags and usage
OS fingerprintingLists of fingerprints for passive fingerprint monitoring
SANS TCP/IP Pocket Reference GuideTCP/IP and Tcpdump Flyer (cheat sheet)
SANS IPv6 TCP-IP Pocket GuideIPv6 Flyer (cheat sheet)
Lib(Pcap/dnet/net) applications and resourcesList of networking applications (Bill Stearns)
Sys-Security Group whitepapersIP security related research
SARSmurf Amplifier Registry
Ethereal display filtersFiltering expressions for ethereal and tethereal
BPF filtersPCAP filtering expression syntax
Port numbers
IANA Port numbersList of TCP & UDP port numbers registered
Trojan port listList of common TCP & UDP trojan's ports (G-Lock)
Trojan ports listList of common TCP & UDP trojan's ports (DoShelp)
Trojan list sorted on trojan portCommon trojan's ports list (various alternatives)
Trojan port listCommon trojan's ports list plus other references
Trojan port listNeohapsis