SlideShare a Scribd company logo
SharkFest ‘16 • Computer History Museum • June 13-16, 2016
SharkFest ‘16
Top 5 False Positives
Jasper Bongertz
Thursday, June 16, 2016
Expert Analyst | Airbus Defence and Space CyberSecurity
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
Agenda
1. Negative Delta Times
2. Frame size and checksum problems
3. Retransmissions and Duplicate ACKs
4. Zero Window
5. Retransmission cost
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
1. Negative Delta Times
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
1 - Wireshark Demo
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
2. Frame size and checksum
problems
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
2 - Wireshark Demo
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
False Positive 2 explained
The offloading effect
Application
Operating System
NIC driver
Application
Operating System
NIC driver
Dum
pcap
Sender Receiver
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
3. Retransmissions and Dup ACKs
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
3 – Wireshark Demo
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
False Positive 3 explained (1/3)
Mirror
Port Monitor
Port
SPAN with a single port
mirrored
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
False Positive 3 explained (2/3)
Mirror
Port Monitor
Port
Mirror
Port
SPAN with two ports mirrored
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
False Positive 3 explained (3/3)
Mirror
Port Monitor
Port
Mirror
Port
SPAN with two ports mirrored
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
4. Zero Window
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
4 – Wireshark Demo
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
5. Retransmission cost
SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay
5 – Wireshark Demo
SharkFest ‘16 • Computer History Museum • June 13-16, 2016
Q&A
Mail: jasper@packet-foo.com
Web: blog.packet-foo.com
Twitter: @packetjay

More Related Content

PPT
Automated Penetration Testing With Core Impact
PPT
PPT
Automated Penetration Testing With The Metasploit Framework
PDF
Rapid7 NERC-CIP Compliance Guide
PDF
Vulnerability to Disasters
ODP
PPTX
Vulnerability Assesment
PPTX
Introduction to Intrusion detection and prevention system for network
Automated Penetration Testing With Core Impact
Automated Penetration Testing With The Metasploit Framework
Rapid7 NERC-CIP Compliance Guide
Vulnerability to Disasters
Vulnerability Assesment
Introduction to Intrusion detection and prevention system for network

Recently uploaded (20)

PPTX
1402_iCSC_-_RESTful_Web_APIs_--_Josef_Hammer.pptx
PDF
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
PDF
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
PPTX
Reading as a good Form of Recreation
PPTX
Introduction to cybersecurity and digital nettiquette
PPTX
Layers_of_the_Earth_Grade7.pptx class by
PPTX
TITLE DEFENSE entitle the impact of social media on education
PPTX
Internet Safety for Seniors presentation
PPTX
t_and_OpenAI_Combined_two_pressentations
PDF
The Ikigai Template _ Recalibrate How You Spend Your Time.pdf
PDF
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
PPTX
Mathew Digital SEO Checklist Guidlines 2025
PDF
Alethe Consulting Corporate Profile and Solution Aproach
DOCX
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...
PPTX
The-Importance-of-School-Sanitation.pptx
PPTX
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
PDF
Buy Cash App Verified Accounts Instantly – Secure Crypto Deal.pdf
PPTX
Cyber Hygine IN organizations in MSME or
PDF
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
PPT
12 Things That Make People Trust a Website Instantly
1402_iCSC_-_RESTful_Web_APIs_--_Josef_Hammer.pptx
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
Reading as a good Form of Recreation
Introduction to cybersecurity and digital nettiquette
Layers_of_the_Earth_Grade7.pptx class by
TITLE DEFENSE entitle the impact of social media on education
Internet Safety for Seniors presentation
t_and_OpenAI_Combined_two_pressentations
The Ikigai Template _ Recalibrate How You Spend Your Time.pdf
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
Mathew Digital SEO Checklist Guidlines 2025
Alethe Consulting Corporate Profile and Solution Aproach
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...
The-Importance-of-School-Sanitation.pptx
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
Buy Cash App Verified Accounts Instantly – Secure Crypto Deal.pdf
Cyber Hygine IN organizations in MSME or
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
12 Things That Make People Trust a Website Instantly
Ad
Ad

Top 5 false positives

  • 1. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 SharkFest ‘16 Top 5 False Positives Jasper Bongertz Thursday, June 16, 2016 Expert Analyst | Airbus Defence and Space CyberSecurity
  • 2. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay Agenda 1. Negative Delta Times 2. Frame size and checksum problems 3. Retransmissions and Duplicate ACKs 4. Zero Window 5. Retransmission cost
  • 3. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 1. Negative Delta Times
  • 4. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 1 - Wireshark Demo
  • 5. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 2. Frame size and checksum problems
  • 6. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 2 - Wireshark Demo
  • 7. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay False Positive 2 explained The offloading effect Application Operating System NIC driver Application Operating System NIC driver Dum pcap Sender Receiver
  • 8. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 3. Retransmissions and Dup ACKs
  • 9. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 3 – Wireshark Demo
  • 10. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay False Positive 3 explained (1/3) Mirror Port Monitor Port SPAN with a single port mirrored
  • 11. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay False Positive 3 explained (2/3) Mirror Port Monitor Port Mirror Port SPAN with two ports mirrored
  • 12. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay False Positive 3 explained (3/3) Mirror Port Monitor Port Mirror Port SPAN with two ports mirrored
  • 13. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 4. Zero Window
  • 14. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 4 – Wireshark Demo
  • 15. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 5. Retransmission cost
  • 16. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 @packetjay 5 – Wireshark Demo
  • 17. SharkFest ‘16 • Computer History Museum • June 13-16, 2016 Q&A Mail: jasper@packet-foo.com Web: blog.packet-foo.com Twitter: @packetjay

Editor's Notes

  • #18: Background Photo: Flickr user Fredrik Andreasson