Passive Application Mapping
- Abstract
- PAM is the ability to identify a service that is being offered on a host by passively analyzing its traffic. Meaning we don't generate any traffic from our utility to determine what is being offering. This gives us the ability to safely map a host where scanning has the potential of causing damage to a server. As traffic on a network is watched, a PAM sensor will detect certain characteristics of what you would expect an application to generate. By doing this, PAM can make a determination as to what is being offered. Knowing what service is being attacked and its version gives us invaluable information for the intrusion analysis process. With this information PAM has great potential to reduce the likelihood of error when analyzing security events.