Re: (no subject)



Joe Holden wrote:
[ ... ]
I'm looking at creating an intrusion detection system, similiar to
portsentry, however using bpf/tcpdump to monitor all traffic, without
needing to listen on those ports, it will be run on a border router, and
as such will need to check for incoming packets destined for other
machines too, and blackhole/add ipfw rules as needed. Are there any
tools like this currently available, or a number of tools I can put
together to create something like this?

Check out /usr/ports/net/honeyd and the Honeynet project...

--
-Chuck
_______________________________________________
freebsd-isp@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-isp
To unsubscribe, send any mail to "freebsd-isp-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: (no subject)
    ... portsentry, however using bpf/tcpdump to monitor all traffic, without ... needing to listen on those ports, it will be run on a border router, and ...
    (freebsd-net)
  • Re: network security related question
    ... Vitorio Okio wrote: ... to specify precisely which ports you wish to monitor, ... including the entire 65,000 some ports. ... past six months of blindly fumbling around the file structure searching ...
    (Ubuntu)
  • Re: Yamaha MSP10s vs. Mackie HR824s?
    ... What mechanism generates this 50% THD? ... That is in fact why ports work - their output is different from that of the ... Learn to trust your monitor in some sense ...
    (rec.audio.pro)
  • Re: Remote debugging on Windows Vista RC2 - firewall configuration fai
    ... After running the remote debugger setup wizard to enable remote debugging ... from machines in my local subnet, I started the remote debugging monitor. ... list of ports that need to be unblocked. ... "Could not configure the Windows firewall. ...
    (microsoft.public.vc.debugger)
  • Re: Problems removing printers and ports from a clustered printser
    ... Windows Printing Team ... This is unique to HP IP Ports, as, we have no problems ... There are some KBs available on removing monitor entries on clustered ...
    (microsoft.public.windows.server.clustering)