From: Mart Frauenlob <mart.frauenlob@chello.at>
To: netfilter@vger.kernel.org
Subject: Re: Advanced Logging
Date: Thu, 03 Jun 2010 22:17:15 +0200 [thread overview]
Message-ID: <4C080DCB.9020507@chello.at> (raw)
In-Reply-To: <AANLkTikt1N0vb0Y0S_akVrvvcboyXfEjU_97tqgEK0jz@mail.gmail.com>
On 03.06.2010 20:15, ratheesh k wrote:
> 2010/5/30 Tomáš Vlček <tomasvlcek@gmail.com>:
>>> I have implemented firewall in my linux machine using
>>> iptables . It is able to prevent attacks and LOG just before dropping
>>> packets . Since i know a little about iptables , i could go thru
>>> /var/log/messages and find out information about attacks . Is there
>>> any application which will analyze logs and give a brief information
>>> to user about the attacks ?
>>>
>>> For example , suppose there was a syn flood attack ,the application
>>> should analyse the /var/log/messages or by some means should know
>>> about the attack and let the user know about that .If there is no
>>> application , could you give some hints on how to develop an
>>> application .Any comment is appreciated .
>> Maybe psad (Port Scan Attack Detector) is that what are you looking
>> for. Check http://cipherdyne.org/psad/index.html.
>
> I gone through the link . It seems to be heavy for my embedded
application .
>
> My embedded box is a router with two inerfaces - wan0 and lan0 . I
> should get information regarding various attacks tried on lan clients
> .I have some implementation in mind .(see below )
>
> 1 Is there any tool fit my requirement or there any tool , i can do
> a little modification in code and use .
> 2 . Is my idea feasible to implement ? . Is it worth implementing ,
> because it is run as part of softirq_rx kernel thread . Will it dampen
> performance ?
> 3 . Could i do this as part of connection tracking module . If , could
> you guide a little ?
>
snort (snort.org) comes into my mind here.
afaik it has the ability to create inline iptables rules.
maybe worth a look?
best regards
mart
next prev parent reply other threads:[~2010-06-03 20:17 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-05-30 14:28 Advanced Logging ratheesh k
2010-05-30 16:22 ` Curby
2010-05-30 18:19 ` Tomáš Vlček
2010-06-03 18:15 ` ratheesh k
2010-06-03 19:02 ` Jan Engelhardt
2010-06-04 2:17 ` ratheesh k
2010-06-03 20:17 ` Mart Frauenlob [this message]
2010-06-03 21:16 ` Mart Frauenlob
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4C080DCB.9020507@chello.at \
--to=mart.frauenlob@chello.at \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.