Ping Sweeps And Port Scans

Ping Sweeps & Port Scans:
Potential Dangers and Defense Strategies


Ping Sweeps & Port Scans
While running businesses, owners must be aware of crucial security threats that their ...view middle of the document...

An individual, thereafter, can use various utilities on the internet to exploit identified “open doors” within a system and gain access to sensitive information as explained in the following paragraphs.
a) Ping Sweeps
A ping sweep is a kind of network probe where an individual sends a set of “ICMP ECHO” packets to a range of machines so as to establish which machines are alive and which ones are not. Hence, it is an attempt to establish which machines in a network are actually on and responding before a hacker can launch his attack on running machines. Although intruders can use ping sweeps to conduct illegal activities, there are legitimate reasons for conducting them. For instance, a network administrator may conduct a ping sweep so as to establish active machines on the network for diagnostic purposes. Teo (2000) assert that most utilities that can perform a ping sweep - including fping - can also perform a DNS search on all IP addresses and generate endpoints names. This crucial information will then allow an attacker to launch an attack on the machine of much preference.
Detection and Defense against Ping Sweeps
The first step in reducing network attacks on a particular system is to detect then attempt to establish proper ways of eliminating the vulnerabilities. Ping sweeps can be detected through various methods such as looking for ARP packets using EtherPeek NX and EtherPeek tools (Wild Packets, 2002). This involves the creation of a filter searching for ARP packets that are usually easy to spot, which are then looked into in order to establish the senders IP address. Ippl is an IP protocol logger that runs in the background and listens for packets; hence, it is high profile ping sweep detection tool (Teo, 2002).
b) Port Scans
A port scan is another common network probe that is generally used by intruders to establish services that are actually running on the target machine (SANS Institute, 2002). Port scans allow intruders to establish vulnerable services in machines where attacks can be successfully launched. As such, a port scan refers to a process where a hacker attempts to establish a connection with target machine on various TCP or UDP ports in order to spot potential vulnerabilities of the system (Wild Packets, 2002). Port scans are generally easy to perform since it involves connecting to a series of ports on the target machine and identifying the ones that respond. Programmers can actually write a simple port scanner in a few minutes, but these are usually very easily detected by the operating system on the target machine as describe in the following paragraph.
Detection and Defense against Port Scans
Port scans are legally accepted unless an attacker uses information from a port scan to

Similar Documents

Ping Sweeps And Port Scans Essay

562 words - 3 pages Ping Sweeps and Port Scans James A. Fort SEC 280 Professor Dau July 15, 2012 Ping Sweeps and Port Scans With computer networks becoming larger hackers are looking more and more for ways to illegally gain access to our networks and procure information about our customers that they can use for their gain. Some tools that hackers are using are called ping sweeps and port scans. Now in the hands of Network Administrators these tools are not

Case Study Week 1

600 words - 3 pages other activity in which our systems can still be accessed if we aren’t careful. Specifically, two harmful activities, ping sweeps and port scans can have a major impact on computer systems and can definitely cause worry if they aren’t prevented. Ping sweeps could have a major impact on computer systems because they are the first step of an intruder making his entry (Conklin, White, 2010). A ping sweep sends a ping or an ICMP echo request to the

Funsec Slm Lab01 Essay

452 words - 2 pages Plus, Quick Traceroute, Regular Scan, Slow comprehensive scan © Jones & Bartlett Learning, LLC. NOT FOR SALE OR DISTRIBUTION 2 7. How many different tests (i.e., scripts) did your Intense Scan perform? Ping (or Arp Ping), TCP Port Scan (SYN Stealth), Service Scan, Operating System Detection (OS detection), and Traceroute 8. Based on your interpretation of the Intense Scan, describe the purpose/results of each tests script performed

Cis 333 Lab 1 Essay

342 words - 2 pages vary? TIL = 128 for windows and 64 for unbuntu 5. What is the command line syntax for running an “Intense Scan” with Zenmap on a target subnet of nmap -T4 -A -v -PE -PS22,25,80 -PA21,23,80,3389 6. Name at least five different scans that may be performed from the Zenmap GUI. Document under what circumstances you would choose to run those particular scans. Intense scan ping scan quick scan regular scan