Snort mailing list archives
Portscans in ACID
From: "John Creegan" <jcreegan () questarweb com>
Date: Mon, 15 Sep 2003 15:05:09 -0500
I'm going to ask and answer a question here at the same time: I've taken the step from the FAQ (6.16). With ACID I see lots of portscan event detail, so I'm sure the portscan data is going to the database properly. Why doesn't the portscan line on the ACID main page show any activity when there are portscan alerts in the DB? Looking at the acid_common.php page. the function "PrintProtocolProfilGraphs" has a conditional test requiring that at least one percent of all alert traffic be portscan activity before it will show anything. I agree that's a perfectly reasonable conditional to have in place. So I'm bettin' that though I have lots of portscan activity, it represents less than one percent of the total alert activity. When I get the time, I'm going to look over the ACID pages for lots of things... not the least of which is "Why does it take 434 seconds to get a graph of alert data in a DB containing < 40,000 alerts when ACID, apache, php and the DB are all on the localhost and there's barely a discernable increase in the utilization of any system resource?" This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law. If you are not the intended recipient, you should delete this message and are hereby notified that any disclosure,copying, or distribution of this message, or the taking of any action based on it, is strictly prohibited. ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- PortScans in ACID John Creegan (Aug 20)
- <Possible follow-ups>
- Portscans in ACID John Creegan (Sep 15)