| Welcome to bestnetworkmonitoringtool.com |
|
Packet Sniffer for Network Monitoring
Packet sniffer
has a special role to play in network monitoring.
It is essential to have a little insight into
it.
Packet Sniffer, also known as a network analyzer
or a protocol analyzer, or for certain specific
kind of network as Ethernet Sniffer or Wireless
Sniffer is a Computer Hardware or software
which can intercept and prepare a log of traffic
that passes through a digital network or through
a specific part of the network. As the data
flows in packets through the network, the
sniffer catches each packet and analyses and
decodes it in accordance with the appropriate
RFC or any other specification.
In a LAN broadcast system which is wired and
uses hub, anyone can capture the traffic or
certain parts of traffic using a single machine
in the network. Using ARP spoofing, traffic
of other systems on the network which are
connected using switches can be monitored.
For the Network Monitoring, it is preferable
to analyze all the data packets present in
the LAN by the use of the network switch which
also has a monitoring port, whose sole use
is to create an image of all the packets which
pass through any port in the switch. Thus,
in a switch, a shadow port should also be
present if the administrator wants to capture
the data.
In case of Wireless LAN, the administrator
can capture the traffic on some specific channel.
On the wireless LANs and Wired Broadcast,
for capturing the traffic which is neither
unicast traffic which is sent to the machine
with sniffer software, nor multicast traffic
which is send to multiple receivers or a group,
nor a broadcast traffic, the Network Adaptor
must be set into promiscuous mode. Only some
sniffers can support this mode, while most
of them don’t support it. In case of
Wireless LANs, for receiving all the packets,
Adaptor must be put into Monitor mode as in
case of Promiscuous Mode, the packets which
are not intended for the service set will
usually be ignored.
Owing to their versatility, packet sniffers
can be used in multiple purposes like Analysis
of Network Problems, detection of Intrusion
Attempts, Network Monitoring, Information
of Network Intrusion, Gathering and Reporting
the statistics of the network, Suspect content
from the network traffic, spying on other
users in the network and collecting the information
like their passwords, reversing the engineer
protocols which are in use in the network,
debugging Client to Server Communications
and debugging protocol implementations in
the network.
|
|