Snort mailing list archives

Portscans in ACID


From: "John Creegan" <jcreegan () questarweb com>
Date: Mon, 15 Sep 2003 15:05:09 -0500

I'm going to ask and answer a question here at the same time:

I've taken the step from the FAQ (6.16).  With ACID I see lots of
portscan event detail, so I'm sure the portscan data is going to the
database properly.  Why doesn't the portscan line on the ACID main page
show any activity when there are portscan alerts in the DB?

Looking at the acid_common.php page. the function
"PrintProtocolProfilGraphs" has a conditional test requiring that at
least one percent of all alert traffic be portscan activity before it
will show anything.  I agree that's a perfectly reasonable conditional
to have in place.  So I'm bettin' that though I have lots of portscan
activity, it represents less than one percent of the total alert
activity.

When I get the time, I'm going to look over the ACID pages for lots of
things... not the least of which is "Why does it take 434 seconds to get
a graph of alert data in a DB containing < 40,000 alerts when ACID,
apache, php and the DB are all on the localhost and there's barely a
discernable increase in the utilization of any system resource?"


This message (including any attachments) contains confidential 
information intended for a specific individual and purpose, 
and is protected by law.  If you are not the intended recipient,
you should delete this message and are hereby notified that any 
disclosure,copying, or distribution of this message, or the taking 
of any action based on it, is strictly prohibited.



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: