Re: SIM Analysis of Firewall Logs
Michael Kinsley <[email protected]> Thu, 27 Sep 2007 13:44:07 -0700
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
s/detections/detection/ -M On Sep 27, 2007, at 12:53 PM, Michael Kinsley wrote: > o might I suggest using GeoIP? One of the requests I receive fairly > often is to identify requests either leaving the country of origin > or going to a particular country. A quick search on CPAN for GeoIP > should get you to the right place. > > If you have competitors it is also reasonable to look for inbound/ > outbound connections from/to them. Although this won't catch people > who go out of their way to avoid detections, its a nice metric to > have handy... and I find most people still treat web browsing as if > it were an anonymous activity. > > good luck. > > -Michael > > _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis