Computer Science · Ch 12 — Security Aspects
Snooping
Snooping
Snooping is the act of secretly listening in on a conversation. In networking, that conversation is the stream of data packets moving across a channel, and snooping means capturing and analysing that traffic without the sender or receiver knowing. The core idea is simple: if you can see the packets, you can read whatever they carry.
A snooping program is a computer utility with network traffic monitoring capability. The hacker taps into a communication channel and picks up all the traffic passing through it. The captured packets are then analysed by the snooping device or software. Critically, after analysis, the tool reproduces the exact traffic packets and places them back into the channel, as if nothing had happened. This makes the attack invisible — neither party realises their communication was intercepted.
The danger depends entirely on encryption. If the data being sent over the network is not encrypted, it is vulnerable to snooping. The damage caused depends on the type of information that leaks — passwords, personal details, financial data, or confidential messages can all be exposed. Unencrypted traffic is essentially an open book to anyone listening on the wire.
Snooping is not always malicious. Network administrators also use it for legitimate purposes, particularly for troubleshooting various network issues. When a network misbehaves, examining the actual traffic helps identify where packets are being dropped, delayed, or corrupted.
Two points worth remembering:
- Snooping is also known as sniffing — the two terms are interchangeable.
- Various snooping software exist that act as network traffic analysers.
- Many network hubs and switches include a SPAN (Sniffer Port Analyser) port function specifically designed for snooping. …