Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask Management Information System Expert

Assignment:

A packet trace of normal network traffic will contain more than just the packets you want to look at. You can apply a display filter to isolate conversations within the trace. For this exercise you will use a trace file of a student at home using a browser to connect to UMUC. The trace captures the traffic that resulted when the student pointed a browser to www.umuc.edu.

If you are using an older, or newer version of ethereal/wireshark, or different OS some of the buttons may be in different windows or positions.

I. Answer the following questions about trace file www_umuc_edu.cap.

1. Download trace file www_umuc_edu.cap (see attached) and open it with Wireshark.

2. Find the first TCP handshake. These are packet numbers ____, _____, and _____.

3. What is the IP address of the host that started the handshake? __________________.

4. What is the TCP port connection pair for this handshake? ______, ______.

5. In the first packet of the handshake, the source port is the ephemeral port this host wants to use for the connection, and the destination port indicates the application the host wants to use on the serving host. What application does the host want to use on the serving host?______________

6. Look at packet number 14. Is this part of the conversation initiated by the first handshake? ______

II. Build a filter to see only the first handshake and the conversation for this connection.

1. Click Analyze (or &Edit& on other versions of ethereal) and select Display Filters from the drop-down list. This brings you to the Edit Display Filters List.

2. Click &Expression&

3. Expand TCP (click the plus sign next to TCP), and highlight &Source or Destination Port&.

4. In the Relation section highlight == .

5. In the Value field type the source port used by the host that initiated the conversation. (The source port should be 1097 in this example).

6. Click &OK&. Now there is a filter string in the Edit Display Filter List window. (The filter string should be &tcp.port == 1097&.)

7. In the Filter name box type &Conversation on 1097&.

8. Click New, then OK. Now you have defined a filter (but not yet applied it).

III. Answer question 4.

The handshake establishes the initial sequence numbers for each connection. Try to follow the sequence numbers in the conversation. Now change the display to show relative sequence numbers:

1. Click Edit and select Preferences from the drop-down list.

2. Drill down into Protocols until you get to TCP.

3. Highlight TCP and select the options, &Analyze TCP sequence numbers& and &Relative sequence numbers and window scaling.& Click OK. Try again to follow the sequence numbers.

4. You cannot see the &next sequence number& in the summary pane for packet number 6. Look for it in the protocol tree pane. Explain why packet number 7 says &ACK =344.&

IV. Extra practice

If you would like to try the same exercise on another trace file without the hints, you can practice on link_to_umuc.cap. This is a trace of a student who is already at www.umuc.edu/students/ clicking on the link to enter the online class. Or, if you want to capture function of Ethereal, you will need to download and install the packet driver, winpcap, from http://netgroup.polito.it/tools . (Note: For privacy or security reasons, the network usage policy at your place of work may not allow you to use packet sniffing software on the network. Do not practice capturing network traffic at work without first checking the policy and obtaining written permission from your employer.)
Attached you may find the files needed for this lab.

This exercise does not specify that you should perform the trace yourselves, because not all of you may have permissions to do that. However, it does encourage those who can make their own captures, and it would be great if some of you could do that and post your traces for discussion.

The prerequisites are listed:

1. Winpcap

If you want to capture your own packets, you will need Winpcap. The download location is given in the last section of the exercise (http://netgroup.polito.it/tools).

Winpcap is the packet driver that sets the network interface in promiscuous mode. Without it, the NIC simply ignores frames not addressed to it, and it won't echo anything up to the packet analyzing application. However, some of you will not be able to install the packet driver (because it talks directly to the network interface hardware and may violate a workstation policy), and others may not be able to use the driver (because of settings in a personal firewall or IDS).

2. Clear browser cache

Those who can run the driver do need to clear their browser cache. Otherwise, the browser will simply display what's in the cache instead of initiating the new connection they are trying to capture.

3. Firewalls

A firewall on your network is unlikely to prevent anyone from capturing files. However, a firewall on the network probably also means you are using someone else's network and shouldn't be capturing files on it anyway, without permission of the owner. On the other hand, a firewall or IDS installed directly on the your computer could prevent you from capturing packets, depending how the firewall/IDS is configured.

You are welcome to view attached Dick Hazeleger's &Packet Sniffing - A Crash Course.& It's especially non-threatening and very encouraging.

Also you may see Mike Schiffman's book, Building Open Source Network Security Tools: Components and Techniques, (Wiley, 2003). This book shows how to use the libraries included with Ethereal (and TCPDump, WinDump, etc) to actually replay packets.

Management Information System, Management Studies

  • Category:- Management Information System
  • Reference No.:- M92065134
  • Price:- $40

Priced at Now at $40, Verified Solution

Have any Question?


Related Questions in Management Information System

Assignment 1 question 1 should cultures within the united

Assignment 1 Question 1 Should cultures within the United States be expected to set aside some traditions or beliefs and integrate under a united social contract? And Why? 300-word response Assignment 2 In response to fe ...

Part 1 - create an 8 slide powerpoint presentation on

Part 1 - Create an 8 slide PowerPoint presentation on foundational concepts specific to physical security. Part 2 - Write 4 pages detailing the framework for the design of an integrated data center. Assessment Instructio ...

Question suppose we have the following measurement

Question : Suppose we have the following measurement: Frequency of floating point(FP) operations is 25%, average CPI of FP operations is equal to 4.0. Average CPI of other instructions is equal to 1.33. Calculate the ove ...

Case building shared services at rr Case : Building Shared Services at RR Communications

Case : Building Shared Services at RR Communications Discussion Questions 1. List the advantages of a single customer service center for RR Communications. 2. Devise an implementation strategy that would guarantee the su ...

1 write a report at least 400 words on how to use data

1. Write a report (at least 400 words) on how to use data mining to help marketing managers specifically. Give a title to your report an interesting title to reflect the theme(s) of your report. You must use a specific b ...

Communication and team decision makingpart 1 sharpening the

Communication and Team Decision Making Part 1: Sharpening the Team Mind: Communication and Collective Intelligence A. What are some of the possible biases and points of error that may arise in team communication systems? ...

Assignment purpose him professionals need to be able to

Assignment Purpose: HIM professionals need to be able to compare and understand different classification systems and understand the challenges of the ACO environment. Assignment Description: Part 1: Complete this mapping ...

Question how does a sequential control process differ from

Question : How does a sequential control process differ from a combination control process? Give one example each of a sequential control process and of a combination control process in which a PLC is used.

Q1 explain identification and assessment of emerging

Q1. Explain identification and assessment of emerging technologies? (APA format required, Turntin check required. Minimum 250 words essay) Q2. What criteria are used to rank current and emerging technology to get the bes ...

Functional vs nonfunctional requirements please respond to

"Functional vs. Nonfunctional Requirements" Please respond to the following: Explain why both functional and nonfunctional requirements are important in IT development. Include at least two (2) examples to support your a ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As