Sniffing
Intercepting and reading network traffic.
5-mark Exam Answer
Sniffing is an e-commerce security threat in which an eavesdropping program monitors information traveling over a network. Laudon and Traver distinguish passive sniffing from the more active man-in-the-middle (MitM) attack.
- 1.Sniffer = eavesdropping program
- 2.Legitimate vs criminal use
- 3.Captures passwords, e-mail, files, reports
- 4.Man-in-the-Middle is more active
- 5.Difficult to detect
A sniffer is a type of eavesdropping program that monitors information traveling over a network. When used legitimately, sniffers can help identify potential network trouble-spots, but when used for criminal purposes, they can be damaging and very difficult to detect. Sniffers enable hackers to steal proprietary information from anywhere on a network, including passwords, e-mail messages, company files, and confidential reports.
Sniffing attacks have caused major data breaches. For instance, in 2013, five hackers were charged in a worldwide scheme that targeted the corporate networks of retail chains such as 7-Eleven and Carrefour SA, using sniffer programs to steal more than 160 million credit card numbers.
E-mail wiretaps are a variation on the sniffing threat. An e-mail wiretap is a method for recording or journaling e-mail traffic generally at the mail server level from any individual. E-mail wiretaps are used by employers to track employee messages and by government agencies to surveil individuals or groups.
A man-in-the-middle (MitM) attack also involves eavesdropping but is more active than a sniffing attack, which typically involves passive monitoring. In a MitM attack, the attacker is able to intercept communications between two parties who believe they are directly communicating with one another, when in fact the attacker is controlling the communications. This allows the attacker to change the contents of the communication.
In 2013, hackers used sniffer programs on the networks of 7-Eleven and Carrefour SA to steal over 160 million credit card numbers — illustrating the large-scale damage possible with sniffing.
Sniffing and man-in-the-middle attacks are eavesdropping threats that intercept network traffic: sniffing is passive monitoring, while MitM is active interception that can alter communications, making both serious threats to e-commerce confidentiality and integrity.
The exam interface follows the university paper pattern: Section A & B carry 5-mark questions; Section C carries objective questions.