Linux Today: Linux News On Internet Time.

More on LinuxToday

psad: Linux Detect And Block Port Scan Attacks In Real Time

Aug 12, 2008, 20:01 (0 Talkback[s])
(Other stories by Vivek Gite)

[ Thanks to An Anonymous Reader for this link. ]

"psad makes use of Netfilter log messages to detect, alert, and (optionally) block port scans and other suspect traffic. For tcp scans psad analyzes tcp flags to determine the scan type (syn, fin, xmas, etc.) and corresponding command line options that could be supplied to nmap to generate such a scan. In addition, psad makes use of many tcp, udp, and icmp signatures contained within the Snort intrusion detection system."

Complete Story

Related Stories: