PASSIVE DETECTION OF MALICIOUS NETWORK-MAPPING SOFTWARE IN COMPUTER NETWORKS
A method includes, in a computer network that includes multiple endpoints, configuring a network element to forward one or more specified packets from a selected endpoint to a detection unit. A malicious network-mapping software running on the selected endpoint is identified by analyzing the forwarded packets in the detection unit.
1 . A method, comprising:
in a computer network that comprises multiple endpoints, configuring a network element to forward one or more specified packets from a selected endpoint to a detection unit; and
identifying a malicious network-mapping software running on the selected endpoint, by analyzing the forwarded packets in the detection unit.
2 . The method according to claim 1 , wherein configuring the network element comprises instructing the network element to send to the selected endpoint a packet that is expected to be discarded by a network interface of the selected endpoint unless the network interface operates in a promiscuous mode, and wherein identifying the network-mapping software comprises detecting that the selected endpoint responded to the packet.
3 . The method according to claim 1 , wherein configuring the network element comprises instructing the network element to send to the selected endpoint a packet having a layer-2 address that does not match the layer-2 address of the selected endpoint, and wherein identifying the network-mapping software comprises detecting that the selected endpoint responded to the packet.
4 . The method according to claim 1 , wherein configuring the network element comprises instructing the network element to forward to the detection unit reverse name resolution queries initiated by the selected endpoint, and wherein identifying the network-mapping software comprises analyzing the reverse name resolution queries.
5 . The method according to claim 4 , wherein identifying the network-mapping software comprises detecting that a rate of the reverse name resolution queries exceeds a threshold.
6 . The method according to claim 4 , wherein identifying the network-mapping software comprises detecting that at least one of the reverse name resolution queries specifies an address in a same subnet as the selected endpoint.
7 . The method according to claim 1 , wherein configuring the network element comprises instructing the network element to forward to the detection unit sniffing announcement packets.
8 . The method according to claim 1 , wherein configuring the network element comprises configuring a physical or virtual network switch.
9 . A method, comprising:
configuring a software module that runs on a node of a computer network to directly access a memory of a Virtual Machine (VM) running on the node; and
using the software module, identifying a malicious network-mapping software running in the VM, by directly accessing the memory of the VM.
10 . The method according to claim 9 , wherein identifying the network-mapping software comprises comparing a process running in the memory of the VM to one or more known network-mapping processes.
11 . The method according to claim 9 , wherein identifying the network-mapping software comprises accessing a virtual network interface in the memory of the VM, and detecting that the virtual network interface is operating in promiscuous mode.
12 . An apparatus, comprising:
an interface for communicating with a computer network that comprises multiple endpoints; and
a processor, which is arranged to configure a network element in the computer network to forward one or more specified packets from a selected endpoint to the apparatus, and to identify a malicious network-mapping software running on the selected endpoint by analyzing the forwarded packets.
13 . The apparatus according to claim 12 , wherein the processor is arranged to instruct the network element to send to the selected endpoint a packet that is expected to be discarded by a network interface of the selected endpoint unless the network interface operates in a promiscuous mode, and to identify the network-mapping software by detecting that the selected endpoint responded to the packet.
14 . The apparatus according to claim 12 , wherein the processor is arranged to instruct the network element to send to the selected endpoint a packet having a layer-2 address that does not match the layer-2 address of the selected endpoint, and to identify the network-mapping software by detecting that the selected endpoint responded to the packet.
15 . The apparatus according to claim 12 , wherein the processor is arranged to instruct the network element to forward reverse name resolution queries initiated by the selected endpoint, and to identify the network-mapping software by analyzing the reverse name resolution queries.
16 . The apparatus according to claim 15 , wherein the processor is arranged to identify the network-mapping software by detecting that a rate of the reverse name resolution queries exceeds a threshold.
17 . The apparatus according to claim 15 , wherein the processor is arranged to identify the network-mapping software by detecting that at least one of the reverse name resolution queries specifies an address in a same subnet as the selected endpoint.
18 . The apparatus according to claim 12 , wherein the processor is arranged to instruct the network element to forward sniffing announcement packets.
19 . The apparatus according to claim 12 , wherein the network element comprises a physical or virtual network switch.
20 . A computer software product, the product comprising a tangible non-transitory computer-readable medium in which program instructions are stored, which instructions, when read by a processor of a detection unit that is connected to a computer network comprising multiple endpoints, cause the processor to configure a network element in the computer network to forward one or more specified packets from a selected endpoint to the detection unit, and to identify a malicious network-mapping software running on the selected endpoint by analyzing the forwarded packets.