cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1433
Views
0
Helpful
7
Replies

Switch Data Attacks

Hello,

 

We have cisco sg300 switches (switched network/ LAN), and we are collecting interface statistics data such as in/out octet, unicast, multicast and broadcast for each switch and each port of the switch.

Can we detect sniffing attack on the switch based on those data?

 

Thanks in advance.

7 Replies 7

balaji.bandi
Hall of Fame
Hall of Fame

No you can not high level  as per i know.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

can you please explain more for us.

 

we searched about this topic and the result was that when data sniffing occurs an increase in data traffic appears which may help us detect it. Is this possible ?

when data sniffing

You mean span the port ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

we have 2 questions:

 

1.can we detect port spanning from data?

 

2. and can we detect any other attack from data (stealing data illegally)?

 

thanks.

1.can we detect port spanning from data?

 

- Sorry i may be missed here, you looking to detect is the port spanned ? or you looking to Data port to span or mirror for sniffing.

 

2. and can we detect any other attack from data (stealing data illegally)?

 

- this is depends on destination port, what software you have to detect this, you need to look more secure solution.

sg300  - your exepctation on this mode too big, so you need to consider if you really looking, then look for Cat 9K switches.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

1. I need to detect if the port spanned.

2. can you explain more please

And if we collect switch data (in/out octet, unicast, multicast and broadcast) and plot them in a graph. Then we monitor this graphs and observe data changes can we figure out if we have any attack on the switch such as data stealing.

1. I need to detect if the port spanned.

 

- if you like to detect port is spanned, based on the config you need to do audit.

 

2- And if we collect switch data (in/out octet, unicast, multicast and broadcast) and plot them in a graph. Then we monitor this graphs and observe data changes can we figure out if we have any attack on the switch such as data stealing.

 

- No by this you will not able to find what you looking for, you need network analyser ( see your network attacked)

you will find many examples.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card