RE: SIM solution - Objectives ? (Firewall logging)

[email protected]
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <[email protected]>
On Wed, 30 May 2007, Dave Ellingsberg wrote:

> B.)  how do you find this host?  In an edu setting we are open and many 
> connections come and go from all parts of the world, and we have to 
> allow them both ways on 80.  So say from a firewall log built messsage 
> how can I tell this is passwords and not normal web traffic?

I use dsniff and urlsnarf to see what the traffic is:
http://www.monkey.org/~dugsong/dsniff/
http://www.monkey.org/~dugsong/dsniff/faq.html

IPAudit shows traffic, host counts, and other interesting data on what's 
going across your network.

http://ipaudit.sourceforge.net/images/ipaudit-web/ipaudit-home.png

Remote host counts will clearly show infected internal hosts that are 
scanning hosts outside. I've gone up and told people their boxes were 
infected before they notice them slowing down.

While this isn't directly logging, these tools allow me to see patterns in 
the traffic and after watching for a week or so, you know what your 
"normal" traffic patterns are and can investigate oddities (through logs 
or other means).

Scott

Scott Delinger, Ph.D.				[email protected]
IT Administrator			http://www.chem.ualberta.ca/~scott
Dept of Chemistry, University of Alberta
Edmonton, Alberta, Canada T6G 2G2
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.