IDS mailing list archives
RE: Difference between Protocol Analyzers -> Packet Sniffers
From: "Seymour, Keith E." <KESeymour () magellanhealth com>
Date: Sat, 27 Mar 2004 14:51:52 -0500
Eric Basically you are right, if the app is able to interpret the data then it's an analyzer. This doesn't mean that it has to do any really advanced interpretation, any level will move it from a sniffer (read only) to an analyzer. "Analyze - To examine methodically by separating into parts and studying their interrelations." So technically counting the packets and types (IP, IPX) could give the app an argument that it is an analyzer. That said, almost everyone uses the two term interchangeably. Examples: http://www.networkintrusion.co.uk/analyzers.htm Ultimately - Don't wrestle with a pig, you won't change his mind and you'll get dirty. Keith -----Original Message----- From: Eric Hines [mailto:eric.hines () appliedwatch com] Sent: Thursday, March 25, 2004 11:33 AM To: focus-ids () securityfocus com; lists () dshield org Subject: Difference between Protocol Analyzers -> Packet Sniffers All, Once upon a time I had a pretty heated argument between myself and another individual on the topic of distinction between protocol analyzers and packet sniffers, and that they are not one in the same. Can anyone provide me some good points on supporting this argument. E.g. Ethereal is a protocol analyzer and Tcpdump is not... I've only been able to articulate that Protocol Analyzers can conduct protocol decoding, whereas Tcpdump can not... Ethereal can provide information on the different fields of the HTTP header and SSL fields.... stuff like that.. Anyone care to jump in here and provide more meat to this argument than this? BRDS, Eric Hines, GCIA CEO, President Applied Watch Technologies, Inc. ------------------------------------------- Eric Hines, GCIA CEO, Chairman Applied Watch Technologies, Inc. web: http://www.appliedwatch.com email: eric.hines () appliedwatch com ------------------------------------------- Direct: (877) 262-7593 - Toll Free x327 Fax: (815) 425-2173 General: (877) 262-7593 (9am-5pm CST) ------------------------------------------- ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ --- --------------------------------------------------------------------------- ---------------------------------------------------------------------------
Current thread:
- Difference between Protocol Analyzers -> Packet Sniffers Eric Hines (Mar 27)
- Re: Difference between Protocol Analyzers -> Packet Sniffers Vincent Bieri (Mar 29)
- Re: Difference between Protocol Analyzers -> Packet Sniffers Joel Snyder (Mar 29)
- Re: Difference between Protocol Analyzers -> Packet Sniffers Adam Baldwin (Mar 29)
- Re: Difference between Protocol Analyzers -> Packet Sniffers Thomas Ptacek (Mar 29)
- Re: Difference between Protocol Analyzers -> Packet Sniffers Jim Matthews (Mar 30)
- <Possible follow-ups>
- RE: Difference between Protocol Analyzers -> Packet Sniffers Palmer, Paul (ISSAtlanta) (Mar 29)
- RE: Difference between Protocol Analyzers -> Packet Sniffers Seymour, Keith E. (Mar 29)
- RE: Difference between Protocol Analyzers -> Packet Sniffers Adam Powers (Mar 29)