Study of Network Analyzer Tools
Presented by
Mr. Sudhakar Mishra, M Tech -IT
Under Guidance of
Prof. S.P. Sonavane
WCE Sangli
Internet
Mr. Anil K. Gupta
CDAC Pune
Network Analyzer
A combination of hardware and software tools what can detect, decode,
and manipulate traffic on the network
Passive monitoring (detection) - Difficult to detect
Active (attack)
Available both free and commercially
Mainly software-based (utilizing OS and NIC)
Also known as sniffer
A program that monitors the data traveling through the network passively
Network Analyzer Used for
Analyze network problems.
Detect network intrusion attempts.
Gain information for effecting a network intrusion.
Monitor network usage.
Gather and report network statistics.
Filter suspect content from network traffic.
Spy on other network users and collect sensitive information such
as passwords (depending on any content encryption methods which
may be in use)
Debug client/server communications.
Debug network protocol implementations.
Wireshark
Features
Available for UNIX and Windows.
Capture live packet data from a network interface.
Open files containing packet data captured with
tcpdump/WinDump, Wireshark, and a number of other
packet capture programs.
URL
https://www.wireshark.org
Microsoft Network Monitor
Features
Support for over 300 public and Microsoft proprietary
Simultaneous capture sessions
Verify Wi-Fi coverage
Locate Wi-Fi devices and detect rogue Access Points
URL
http://www.xirrus.com
protocols
Features
Xirrus Wi-Fi Inspector
Can be used to search for Wi-Fi networks
Manage and troubleshoot connections
Result of each probe is classified using green, red, or black colors to
quickly show whether the probe was successful, had a negative result or
wasnt able to complete.
URL
http://www.softinventive.com/products/total-network-monitor/
Total Network Monitor
Features
Continuously monitors hosts and services on the local network
Notifying you of any issues that require attention via a detailed
report of the problem
A Wireless Monitor Mode and sniffing of promiscuous mode
traffic
URL
https://www.wireshark.org
Angry IP Scanner
Features
Facilitates IP address and port scanning
Used to scan a range of IP addresses to find
hosts that are alive
URL
http://angryip.org
PRTG Network Monitor Freeware
Features
Comprehensive Network Monitoring which offers more than 170
sensor types
Flexible Alerting, including 9 different notification methods
In-Depth Reporting,
URL
http://www.paessler.com/prtg
Zenoss Core
Features
IT monitoring platform that monitors applications, servers, storage,
networking and virtualization
Performance event handling system
Flexible Alerting, including 9 different notification methods
In-Depth Reporting,
URL
http://sourceforge.net/projects/zenoss/
Fiddler
Features
Web debugging tool that captures HTTP traffic
Performance Testing
Web Session Manipulation
Security Testing
URL
http://www.telerik.com/fiddler
Capsa Free
Features
Real-time packet capture as well as the ability to save data transmitted over local
networks, including wired network and wireless network like 802.11a/b/g/n
Easy to use Overview Dashboard
Suspicious hosts can be detected and diagnosed enabling you to pinpoint network
problems in seconds
Map the traffic, IP address, and MAC of each host on the network,
Identify "Top Talkers" by monitoring network bandwidth
URL
http://www.colasoft.com/capsa-free/