Can I use Wireshark to trace the origin of a DDoS attack?

Responsive Ad Header

Question

Grade: Education Subject: Ddos
Can I use Wireshark to trace the origin of a DDoS attack?
Asked by:
57 Viewed 57 Answers

Answer (57)

Best Answer
(363)
Tracing the *true* origin of a DDoS attack is extremely difficult due to the distributed nature of botnets and the use of spoofed IP addresses. Wireshark can show you the source IP addresses seen on your network, but these are often not the actual attackers. Network path tracing tools (traceroute) can provide some information, but are also easily circumvented.