Re: SIM Analysis of Firewall Logs

Michael Kinsley <[email protected]> Thu, 27 Sep 2007 13:44:07 -0700
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <[email protected]>
s/detections/detection/

-M
On Sep 27, 2007, at 12:53 PM, Michael Kinsley wrote:

> o might I suggest using GeoIP? One of the requests I receive fairly  
> often is to identify requests either leaving the country of origin  
> or going to a particular country.  A quick search on CPAN for GeoIP  
> should get you to the right place.
>
> If you have competitors it is also reasonable to look for inbound/ 
> outbound connections from/to them. Although this won't catch people  
> who go out of their way to avoid detections, its a nice metric to  
> have handy... and I find most people still treat web browsing as if  
> it were an anonymous activity.
>
> good luck.
>
> -Michael
>
>

_______________________________________________
LogAnalysis mailing list
[email protected]
http://www.loganalysis.org/mailman/listinfo/loganalysis