Question: Q4. Network Traffic Analysis (20 points) Use Network Miner program to load and study the PCAP file uploaded with the assignment on D2L. PCAP=> DoS-15m-12h_1
Q4. Network Traffic Analysis (20 points)
Use Network Miner program to load and study the PCAP file uploaded with the assignment on D2L. PCAP=> DoS-15m-12h_1
a. List 3 observations about the network, in terms of number of hosts, IP addresses, type of traffic/protocol. (6 points)
b. Extract and list 4 sets of credentials (user name / passwords) that communicated over the network. (4 points)
c. Examine host 172.27.224.99
1. What OS is running on that host? (2 points)
2. What can you tell about traffic from and to that host? (4 points)
3. This is host is carrying a DoS attack, can you identify the victim hosts in the network? (4 points)
eth2dump-pingFloodDDoS-15m-12h_1.pcap o + TISTA TED Apply a display filter ... No. Time Source Destination | Protocol Length| Info 902... 43198.566869 172.27.224.250 172.27.224.70 Modbu... 85 Response: Tri 902... 43198.775110 172.27.224.251 172.27.224.250 TCP 60 49911 + 502 902.. 43198.780339 172.27.224.70 172.27.224.250 TCP 60 49179 - 502 902... 43198.785004 172.27.224.250 172.27.224.251 TCP 60 502 + 49911 902... 43198.785982 172.27.224.250 172.27.224.251 TCP 60 502 + 49911 902... 43198.786002 172.27.224.251 172.27.224.250 TCP 60 49911 + 502 902... 43198.786213 172.27.224.250 172.27.224.251 TCP 60 502 + 49911 902... 43198.794908 172.27.224.250 172.27.224.251 TCP 60 502 + 49911 902... 43198.874788 172.27.224.70 172.27.224.250 Modbu... 66 Query: Tr 902... 43198.886830 172.27.224.250 172.27.224.70 Modbu... 85 Response: Tr 902... 43199.092367 172.27.224.70 172.27.224.250 TCP 60 49179 + 502 902... 43199.187913 172.27.224.70 172.27.224.250 Modbu... 66 Query: Tr 902... 43199.196245 172.27.224.250 172.27.224.70 Modbu... 85 Response: Tr! 0 902... 43199.404350 172.27.224.70 172.27.224.250 TCP 60 49179 - 502 ACK] Frame 1: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) Ethernet II, Src: VMware_9d:9e:9 (00:0c:29:9d:9e:9e), Dst: Telemech_09:51:36 (00:80:f4:09:51:3 Internet Protocol Version 4, Src: 172.27.224.70, Dst: 172.27.224.250 Transmission Control Protocol, Src Port: 49179, Dst Port: 502, Seq: 1, Ack: 1, Len: 0 ) E F 0000 2010 0020 0030 00 80 f4 09 51 36 00 29 9d 9e 9e 08 60 45 00 00 28 16 c6 40 00 80 06 ca 91 ac 1b eo 46 ac 1b e fa co 1b 01 f6 61 ca ac 96 91 76 f4 1b 50 10 ff 13 41 43 00 00 00 00 00 00 00 00 Q; (@ a AC ...V Sorting "Source"... Packets: 902790 - Displayed: 902790 (100.0%) Profile: Default eth2dump-pingFloodDDoS-15m-12h_1.pcap o + TISTA TED Apply a display filter ... No. Time Source Destination | Protocol Length| Info 902... 43198.566869 172.27.224.250 172.27.224.70 Modbu... 85 Response: Tri 902... 43198.775110 172.27.224.251 172.27.224.250 TCP 60 49911 + 502 902.. 43198.780339 172.27.224.70 172.27.224.250 TCP 60 49179 - 502 902... 43198.785004 172.27.224.250 172.27.224.251 TCP 60 502 + 49911 902... 43198.785982 172.27.224.250 172.27.224.251 TCP 60 502 + 49911 902... 43198.786002 172.27.224.251 172.27.224.250 TCP 60 49911 + 502 902... 43198.786213 172.27.224.250 172.27.224.251 TCP 60 502 + 49911 902... 43198.794908 172.27.224.250 172.27.224.251 TCP 60 502 + 49911 902... 43198.874788 172.27.224.70 172.27.224.250 Modbu... 66 Query: Tr 902... 43198.886830 172.27.224.250 172.27.224.70 Modbu... 85 Response: Tr 902... 43199.092367 172.27.224.70 172.27.224.250 TCP 60 49179 + 502 902... 43199.187913 172.27.224.70 172.27.224.250 Modbu... 66 Query: Tr 902... 43199.196245 172.27.224.250 172.27.224.70 Modbu... 85 Response: Tr! 0 902... 43199.404350 172.27.224.70 172.27.224.250 TCP 60 49179 - 502 ACK] Frame 1: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) Ethernet II, Src: VMware_9d:9e:9 (00:0c:29:9d:9e:9e), Dst: Telemech_09:51:36 (00:80:f4:09:51:3 Internet Protocol Version 4, Src: 172.27.224.70, Dst: 172.27.224.250 Transmission Control Protocol, Src Port: 49179, Dst Port: 502, Seq: 1, Ack: 1, Len: 0 ) E F 0000 2010 0020 0030 00 80 f4 09 51 36 00 29 9d 9e 9e 08 60 45 00 00 28 16 c6 40 00 80 06 ca 91 ac 1b eo 46 ac 1b e fa co 1b 01 f6 61 ca ac 96 91 76 f4 1b 50 10 ff 13 41 43 00 00 00 00 00 00 00 00 Q; (@ a AC ...V Sorting "Source"... Packets: 902790 - Displayed: 902790 (100.0%) Profile: Default