IDS mailing list archives

RE: Difference between Protocol Analyzers -> Packet Sniffers


From: "Seymour, Keith E." <KESeymour () magellanhealth com>
Date: Sat, 27 Mar 2004 14:51:52 -0500

Eric

Basically you are right, if the app is able to interpret the data then
it's an analyzer. This doesn't mean that it has to do any really
advanced interpretation, any level will move it from a sniffer (read
only) to an analyzer.

"Analyze - To examine methodically by separating into parts and studying
their interrelations."

So technically counting the packets and types (IP, IPX) could give the
app an argument that it is an analyzer.

That said, almost everyone uses the two term interchangeably.


Examples:

http://www.networkintrusion.co.uk/analyzers.htm


Ultimately - Don't wrestle with a pig, you won't change his mind and
you'll get dirty.

Keith


-----Original Message-----
From: Eric Hines [mailto:eric.hines () appliedwatch com] 
Sent: Thursday, March 25, 2004 11:33 AM
To: focus-ids () securityfocus com; lists () dshield org
Subject: Difference between Protocol Analyzers -> Packet Sniffers

All,

Once upon a time I had a pretty heated argument between myself and
another individual on the topic of distinction between protocol
analyzers and packet sniffers, and that they are not one in the same.

Can anyone provide me some good points on supporting this argument. E.g.
Ethereal is a protocol analyzer and Tcpdump is not... 

I've only been able to articulate that Protocol Analyzers can conduct
protocol decoding, whereas Tcpdump can not... Ethereal can provide
information on the different fields of the HTTP header and SSL
fields.... stuff like that.. Anyone care to jump in here and provide
more meat to this argument than this?

BRDS,
Eric Hines, GCIA
CEO, President
Applied Watch Technologies, Inc.


-------------------------------------------
Eric Hines, GCIA
CEO, Chairman
Applied Watch Technologies, Inc.
web: http://www.appliedwatch.com
email: eric.hines () appliedwatch com
-------------------------------------------
Direct: (877) 262-7593 - Toll Free x327
Fax: (815) 425-2173
General: (877) 262-7593 (9am-5pm CST)
-------------------------------------------






------------------------------------------------------------------------
---

------------------------------------------------------------------------
---



---------------------------------------------------------------------------

---------------------------------------------------------------------------


Current thread: