0% found this document useful (0 votes)
2 views2 pages

Questionnaire

The document outlines a guided tour and questionnaire for a PCAP file analyzer developed for an MSc Computer Security project. It provides step-by-step instructions for using the tool to detect malicious behavior in network traffic and includes a questionnaire to gather user feedback on the tool's performance and features. Users are encouraged to explore the tool independently after completing the guided tour.

Uploaded by

gutapantashaa
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views2 pages

Questionnaire

The document outlines a guided tour and questionnaire for a PCAP file analyzer developed for an MSc Computer Security project. It provides step-by-step instructions for using the tool to detect malicious behavior in network traffic and includes a questionnaire to gather user feedback on the tool's performance and features. Users are encouraged to explore the tool independently after completing the guided tour.

Uploaded by

gutapantashaa
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd

Daniel Botterill

PCAP Analyzer Tour & Questionnaire

For my MSc Computer Security summary project I have developed an analyzer of PCAP
files which are basically a dump of network traffic. The analyzer has a number of features to
detect malicious behaviour within the PCAP file and to report it. This document will give you a
tour of some of the functionality, getting you to fill in some questions about malware
behaviour, the answers to which you will be partially guided towards so that you can become
familiar with the tool. You should then use the tool individually and then fill in a short
questionnaire of your experience with using the tool. Thank you for your time in completing
this tour and questionnaire it is greatly appreciated.

Guided Tour
1. Read [Link] on how to install and run the PCAP analyzer

2. Click the File menu and choose Open PCAP File and select [Link] from the main
folder

3. Click on the Packet Viewer tab you see the list of all packets within the PCAP file, how
many packets are there?

4. In the filter field at the top type “http”, locate packet 1339, what is the HTTP reply
code?

5. Click on the Streams Viewer tab; select the IRC Streams tab, what is the nickname and
username for the first IRC stream?

6. Click on the Background Traffic tab; select the UDP Streams tab, what are the two types
of packets identified as being background traffic?

7. Click on the Download PCAP Files tab, what is an example of a file that is likely to be an
executable?

8. Click on the Blacklisted Addresses tab, select the domain [Link], and then the
Streams Viewer tab at the bottom, what is the number of packets and total length of the
16th TCP stream?

9. Click on the Domain Name Flux tab, select the Gram Distribution Detection tab, select
the Feature Comparison tab, and choose Unigram Score and Bigram Score in the two
drop down lists at the top, press Update, by looking at the scatter plot what is roughly
the average Unigram Score and Bigram score for Torpig?

[Link] still on the Domain Name Flux tab, whilst still on Gram Distribution Detection tab,
choose Unigram Distribution from the bottom drop down list, what is the most frequent
character for the dataset Top 10000 English Words?

[Link] on the Traffic Patterns tab, select Constant HTTP Requests, to how many different
IP addresses is the first POST HTTP request sent to?

[Link] on the Port Knocks tab, a port knock has been attempted on [Link] to which
port was it attempted and what type of port knock?

[Link] on the Network Map tab, what are the short textual summaries that appear next to
the computer [Link]?

[Link] still on Network Map, hover over the computer from the previous question, how
many TCP streams and UDP streams features this IP address?
[Link] on the Malware Summary tab, how many DNS No Such Names were identified?
What are the two domains attempted that resulted in DNS No Such Names?
Now that you completed the guided tour you should use the tool yourself individually, not
all of the features were demonstrated in the guided tour as it is only in other PCAP files do
some malware behaviour appear.

Questionnaire
Please fill in the following questions about your experience with the PCAP Analyzer. For
those with a mark out of 10 if there is a particular feature that affects the mark then please
identify this individually.

Overall how would you rate the product out of 10?

How would you rate the performance of the tool out of 10?

How would you rate the user interface for ease of use and amount of information show out of
10?

What improvements would you like to see in the next release of the analyzer?

What additional features would you like to see in the next release of the analyzer?

You might also like