Register for Network Security-Vegas by Sept. 3 for $250 discount. >> More Info
the most trusted source for computer security training, certification and research


Passive Application Mapping

Click Here
Abstract
PAM is the ability to identify a service that is being offered on a host by passively analyzing its traffic. Meaning we don't generate any traffic from our utility to determine what is being offering. This gives us the ability to safely map a host where scanning has the potential of causing damage to a server. As traffic on a network is watched, a PAM sensor will detect certain characteristics of what you would expect an application to generate. By doing this, PAM can make a determination as to what is being offered. Knowing what service is being attacked and its version gives us invaluable information for the intrusion analysis process. With this information PAM has great potential to reduce the likelihood of error when analyzing security events.
<<Reading Room Home     <<Back to Category

Contact us: (301) 654-SANS(7267)
Monday - Friday 9am-8pm EST/EDT