Security Basics mailing list archives

Aggreate Traffic -detailed level


From: "ListServ" <knothead () clarksoncollege edu>
Date: Fri, 16 Sep 2005 08:19:05 -0500

Greetings: 

I have a dorm environment with about 100 machines that I need to break down the traffic into different kinds of 
traffic. Yesterday our dear students decided to fire of some sort of p2p traffic or something of that nature. 

What I need is a recommendation a to traffic analysis tool(s) that breaks down the protocols to exactly what is going 
on. We are using IPCop which has excellent reporting capacity as far as daily, weekly and yearly runs but I need to 
drill to a more detailed level. 

 

I have a XP machine running with  winpcap and ethreal and watching things right now buth but I need something a more 
robust. Maybe like IPAudit. Can some point me to similiar programs that will monitor a n/w on a on 24x7 period (as 
IPAudit)?

 

We have been hit twice in the past two months with massive n/w bottlenecks. Once one was a Denial of Service attack. 
This most recent was either downloading of movie file or some type of p2p traffic. 

Suggestions? 

########################## 
Roger Schmeits 
Sr. Network Engineer 
Clarkson College 
http://www.clarksoncollege.edu 
(402) 552-2542 
########################## 
Disclaimer: 

The information contained in this e-mail is privileged and confidential and is intended only for the use of the 
addressee(s) indicated above. Use or disclosure of information e-mailed in error is respectfully prohibited. If you 
have received this e-mail in error, please contact the sender and immediately delete the original message. Thank you.

---
[This E-mail scanned for viruses by Declude Virus]


Current thread: