Security Incidents mailing list archives

Re: traffic logging


From: root () RGFSPARC CR USGS GOV (Robert G. Ferrell)
Date: Wed, 3 May 2000 10:49:06 -0500


I've been seeing a lot of odd traffic on several of my
machines and I was
wondering what you folks suggest for logging traffic on a
single machine.
Several of the machines are Linux boxes, and I'd like the
ability to log in
depth.  Things I'd like to capture would include things like
stealth scans
and odd packets.

Any suggestions?


Not so much for traffic, but I use logcheck for any anomolies in the log
files, and PortSentry to detect and react to port scans.  They can both be
found here:
http://www.psionic.com/

I find iplog to be quite useful, as well:
http://ojnk.sourceforge.net

Cheers,

RGF

Robert G. Ferrell, CISSP
Information Systems Security Officer
National Business Center, US DoI
Robert_G_Ferrell () nbc gov
------------------------------------------------------------
Nothing I have ever said should be construed as even vaguely
representing an official statement by the NBC or DoI.
------------------------------------------------------------


Current thread: