LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-26-2005, 09:07 AM   #1
johnnyde
LQ Newbie
 
Registered: May 2003
Location: India
Distribution: Fedora Core 1
Posts: 17

Rep: Reputation: 0
Question Intrution Detection using Packet Analysis


Hi
i am wondering how to detect intruders using packet analysis. so far in my research on internet i found ways to capture the packet using pcap library (libpcap) and save the data for later analysis.
But how to detect if any intruders where there. Any pointer on the concepts or the techniques used to detect intruders using packet analysis would be very helpful

Thanks in advance
Johnny
 
Old 03-26-2005, 09:33 AM   #2
auximini
Member
 
Registered: Dec 2003
Location: Calgary, AB
Distribution: Any!
Posts: 146

Rep: Reputation: 18
Have you tried snort?

I would also recommend reading "Network Intrusion Detection - An Analysts Handbook"
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Packet Filter to redirect a packet to a user level process akawale Linux - Networking 3 09-01-2006 12:06 PM
how do i read the data in the packet that i have captured after packet capture? gajaykrishnan Programming 23 04-19-2006 05:09 AM
packet fragmentation in packet forwarding code cranium2004 Linux - Networking 0 05-16-2005 04:05 AM
How to change Packet to look like a Windows packet? TimeFade Linux - Networking 10 08-28-2003 08:08 AM
Suggestions for packet sniffer w/ packet viewing? TruckStuff Linux - Networking 5 05-31-2002 09:50 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration