Presentation is loading. Please wait.

Presentation is loading. Please wait.

Xplico: concept, features and demo.

Similar presentations


Presentation on theme: "Xplico: concept, features and demo."— Presentation transcript:

1 Xplico: concept, features and demo.

2 Xplico, NFAT For example, from a pcap file Xplico extracts each (POP, IMAP, SMTP and some webmails protocols), all HTTP contents, each VoIP call (SIP), FTP, TFTP, and so on. Xplico isn’t a network protocol analyzer. Xplico is an open source Network Forensic Analysis Tool (NFAT). The goal of Xplico is extract from an internet traffic capture the applications data contained.

3 Xplico – GNU's State of art
Decoded protocols Jan. 2010

4 Xplico - Layers and protocols supported
March 2010

5 Xplico – Working modes Modes Offline → PCAP Online → Network adapter
From CLI or web interface ./xplico -m rltm -i eth0

6 Xplico – Some screenshots

7 Xplico - Architecture Dema, Xplico, XI, DB

8 Real time demo of Xplico.
Xplico - Demo Real time demo of Xplico.

9 Xplico - Tips & tricks ”No checksum verification mode” available (solving non trustable software/hardware adquiring data systems). [FOR DEVELOPERS] lastdata.txt, index of decoded information. Non decoded flows are stored.

10 Xplico - Resources Downloads tar.gz (sources) DEB Virtualbox image
Wiki Captures Samples repository Forum (supported directly and quickly by developers).

11 Xplico PCAP capture demo of Xplico. Public pcap samplehttp://wiki.xplico.org/lib/exe/fetch.php?media=pcap:xplico.org_sample_capture_protocols_supported_in_0.5.5.pcap.bz2

12 Xplico Roadmap Short term: Gmail and VoIP dissectors.
Middle term: IM and p2p dissectors. Long term: advanced adquisition and decoding tools. Contributors are welcome.

13 Comments and questions.


Download ppt "Xplico: concept, features and demo."

Similar presentations


Ads by Google