How to Monitor Employee Web Traffic

How to Monitor Employee Web Traffic thumbnail
Monitoring employee Internet usage is essential for the security of your network.

If you are an employer who provides access to the Internet, you can expect a certain amount of web browsing by your employees. When left unregulated, these web surfing habits--such as shopping or trading in pirated music and movies--can result in decreased worker productivity. This activity can leave your company open to expensive lawsuits and virus attacks.



Another major threat to your business is the occasional transfer of intellectual property or clients' personal information via email to an external computer that is beyond your reach. One way to prevent these potentially disastrous incidents is to set strict guidelines, to monitor your employees' web usage and to inform them that they are being watched.

Instructions

    • 1

      Obtain and install Wireshark on your employees' computers. This is a free packet "sniffer," which scans all Internet activity on a computer and stores the information for you to inspect. Download the program from the Wireshark website. Install Wireshark on each of your employees' computers in "Administrator" mode. Follow the installation file's instructions for installing Wireshark on your system.

    • 2

      After installing Wireshark to monitor all web traffic on your network, go to the "Capture" menu. Click the "Interfaces" menu item. Then click "Stop." If "Stop" is grayed out, then proceed to the "Ethernet" entry (usually marked as "eth0") and click "Options." Check "Capture packets in promiscuous mode." In the input box next to "Capture Filter," type in "tcp port http." Then go to the "Capture File(s)" area and pick a directory location for your capture log file. This is what you will later read to see what websites your employees are accessing. Click "Use multiple files" to put a check by it. Then click "Next file every..." Put 5 in the input box to keep your log files no larger than 5 megabytes. Uncheck "Ring buffer with..." and "Stop capturing after..." Uncheck everything in the "Stop Capture" area. Under the "Name Resolution" area, check "Enable network name resolution." Click "Start".

    • 3

      Check the log files at the end of the day. Go to the directory location where you stored your capture file. Open each of the log files with Wireshark that you wish to investigate. The screen will fill up with log entries. Those entries will include the address of the PC on which an employee was web browsing, and the websites that the employee visited.

Tips & Warnings

  • Do not allow your employees Administrator access on a work computer that is running WireShark. It will enable them to delete the log files.

Related Searches:

References

Resources

  • Photo Credit binary digits - computer science image by drx from Fotolia.com

Comments

You May Also Like

Related Ads

Featured