
7.3.2 Perimeter packet analysis
There are two components to packet analysis: capture and analysis. In
addition to the protocol analysis, reconstruction of the packets is a desir-
able feature, especially in perimeter security. Sniffer is the leading brand
in packet sniffing, but use of tools such as Sniffer and Wildpackets
requires weeks of expensive training. Add in the cost, and these tools can
run anywhere from $2,000 to $40,000, and it may be that such tools
don’t provide the level of reconstruction desired or are too expensive.
They offer many features and toolsets that are clearly outside the scope
of establishing a secure perimeter; they are troubleshooting ...