tcpdump mailing list archives

Re: Data Analysis tools


From: "Thomas Kessler" <thomas.kessler () gmx net>
Date: Wed, 29 Jan 2003 20:51:14 +0100

Hello Michael,

try http://www.comlab.uni-rostock.de/research/tools.html may be it helps you.

Thomas
  ----- Original Message ----- 
  From: Keplinger, Michael A 
  To: Tcpdump-Workers (E-mail) 
  Sent: Wednesday, January 29, 2003 5:13 PM
  Subject: [tcpdump-workers] Data Analysis tools


  Does anyone have any or know of any tools (possible perl scripts, etc.) for anaylzing and trending tcpdump output?  I 
have been developing something myself, but I wanted to see if anyone had something that they were currently using.

  We get an enormous amount of traffic throughout our enterprise and we are using Shadow for more of a reactive role 
rather than a proactive role.  I would like to either develop or find some scripts or otherwise to organize and trend 
this data, as well as compare it against the output of other IDS tools that we use so we can be a little more proactive 
about the tool.

  Any ideas?

  =====================================
  Michael Keplinger
  Information Assurance
  Security Systems Engineer
  michael.keplinger () nmci-isf com

  "Some dumb quote"

Current thread: