Definition

passive reconnaissance

Passive reconnaissance is an attempt to gain information about targeted computers and networks without actively engaging with the systems. In active reconnaissance, in contrast, the attacker engages with the target system, typically conducting a port scan to determine find any open ports.

The term reconnaissance comes from its military use to describe an information-gathering mission. Both types of reconnaissance are sometimes referred to as passive attacks because the purpose is simply to obtain information, rather than to actively exploit the target. However, reconnaissance is often a preliminary step towards an active attempt to exploit the target system.

Methods of passive reconnaissance include:

  • War driving to detect vulnerable wireless networks.
  • Looking for information stored on discarded computers and other devices.
  • Masquerading as an authorized network user.

Both active and passive reconnaissance are also used for ethical hacking, in which white hat hackers use attack methods to determine system vulnerabilities so that problems can be taken care of before the system falls prey to a real attack.

The simplest way to protect yourself from port scan attacks or reconnaissance attacks is to use a good firewall and intrusion prevention system (IPS). The firewall controls which ports are exposed and to whom they are visible, while the IPS will detect port scans in progress and shut them down before they are able to gain a full map of your network.

See also: well-known port number, vulnerability analysis (vulnerability assessment), cracker, hacker

 

Continue reading about active reconnaissance:

> Reconnaissance attacks are covered in this introduction to network security.

>eTorials also covers reconnaissance attacks.

This was last updated in April 2012
Posted by: Margaret Rouse

Related Terms

Definitions

  • Heartbleed

    - Heartbleed is a vulnerability in some implementations of OpenSSL. Because OpenSSL is used by approximately 66% of all active websites on the Internet, many experts have called Heartbleed one of the... (SearchSecurity.com)

  • SYN flood (half open attack)

    - SYN flooding is a method that the user of a hostile client program can use to conduct a denial-of-service (DoS) attack on a computer server. (SearchSecurity.com)

  • Microsoft Security Essentials (MSE)

    - Microsoft Security Essentials (MSE) is an antimalware software product made by Microsoft that provides protection for client computers against viruses, worms, Trojans, spyware and other malicious s... (SearchSecurity.com)

Glossaries

  • Security threats and countermeasures

    - Terms related to security threats, including definitions about anti-virus programs or firewalls and words and phrases about malware, viruses, Trojans and other security attacks.

  • Internet applications

    - This WhatIs.com glossary contains terms related to Internet applications, including definitions about Software as a Service (SaaS) delivery models and words and phrases about web sites, e-commerce ...

Ask a Question About passive reconnaissancePowered by ITKnowledgeExchange.com

Get answers from your peers on your most technical challenges

Tech TalkComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.