psad: Linux Detect And Block Port Scan Attacks In Real TimeAug 12, 2008, 20:01 (0 Talkback[s])
(Other stories by Vivek Gite)
WEBINAR: On-demand Event
Replace Oracle with the NoSQL Engagement Database: Why and how leading companies are making the switch REGISTER >
[ Thanks to An Anonymous Reader for this link. ]
"psad makes use of Netfilter log messages to detect, alert, and (optionally) block port scans and other suspect traffic. For tcp scans psad analyzes tcp flags to determine the scan type (syn, fin, xmas, etc.) and corresponding command line options that could be supplied to nmap to generate such a scan. In addition, psad makes use of many tcp, udp, and icmp signatures contained within the Snort intrusion detection system."
0 Talkback[s] (click to add your comment)