Re: [LOGS] Summary of large-scale portscanning detects
Kyle Maxwell <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 16 Aug 2004 09:14:11 -0700 (PDT), Merton Campbell Crockett <[email protected]> wrote: > My apologies to the list but I don't understand the significance of this > summary. It's normal to have systems sweeping through your address space > turning the door handle to see if its unlocked. > > The first block in Sunday's report is, perhaps, the only thing of interest > in the report. Unfortunately, the report format doesn't allow us to see > a complete set of probes targeted at an individual system. I think you may be potentially missing the points. Port scans are normal in the sense that we know they happen. But knowing *what* is being scanned for is useful intelligence, as is any information about interesting scan patterns (such as the one you mention above). This lets people receiving the information make more informed correlations -- is this traffic pattern common to the Internet right now or is it more likely I'm being targeted? The usefulness is similar to the Internet Storm Center and Dshield, allowing people to get a broader view on what specifically is going on across the net. -- Kyle Maxwell [email protected] _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions