Week 2

In this session, we learned about Source of Network-Based Evidence and Principles of Internetworking.

There are many different types of network-based evidence which are:

  1. On the wire
  2. In the air
  3. Switches
  4. Routers
  5. DHCP Server
  6. DNS Server
  7. Authentication Server
  8. NIDS/NIPS
  9. Firewalls
  10. Web Proxies
  11. Application Server
  12. Centralized Log Server
  13. Modem

On the wire refers to physical cabling that carries data over the network. There are 3 different tap types which are vampire tap, surreptitious fibre tap, and infrastructure tap.

In the air works as a wireless station to station signals where it checks radio frequency and infrared to obtain management and control frames, access point names, MAC addresses and traffic analysis.

Switches are physical connection between network segments where it can be used to capture and preserve network, and to mirror traffic from one port to another.

Leave a Reply

Your email address will not be published. Required fields are marked *