How to keep packet sniffers from collecting sensitive data

How to keep packet sniffers from collecting sensitive data

What are the best ways to protect users from packet sniffers that can collect sensitive information like passwords?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

There are two important actions that can protect users from packet sniffers and other eavesdropping attacks.

First, use encryption! If you encrypt sensitive data and passwords while in transit, you'll render packet sniffers useless.

Encryption can be implemented in a number of ways: SSL (HTTPS) connections to Web servers, encrypted SSL or TLS connections to mail servers, or other application-specific techniques. Alternatively, you can use a virtual private network (VPN) to encrypt entire communications links, regardless of protocol.

Second, use a switched network. In this case, a packet sniffer will only be able to eavesdrop on connections taking place on its own local switch port. If you assign each system to an individual switch port, there simply won't be any packets for the packet sniffer to intercept.

More information:

  • Looking to sniff out problem packets? Contributor Scott Sidel recommends Wireshark.
  • Use a packet sniffer to determine whether an email message is encrypted or not.
  • This was first published in April 2007