LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-02-2012, 11:30 PM   #1
anon079
Member
 
Registered: Apr 2012
Location: Alexandria, VA
Distribution: Fedora
Posts: 46

Rep: Reputation: 1
Tools for monitoring network activity.


I'm just getting the hang of things with my Linux VM server and I'd like to find a monitoring tool that will let me view packets, connection attempts from outside, attacks, things of that nature. I realize this is a broad topic that could lead to many other questions but all I'm really looking for are suggestions for open source software that can accomplish the type of things I've mentioned above.
 
Old 05-03-2012, 12:18 AM   #2
0men
Member
 
Registered: Mar 2011
Location: Brisbane
Distribution: Windows 10, Red Hat, Debian
Posts: 183

Rep: Reputation: 22
Hi,

Wireshark is what your after. Tcpdump is alright too, but Wireshark has a nice GUI. I use it for monitoring network traffic and if one of the servers is having the blues.

You might also want to look at this
http://resources.infosecinstitute.co...raffic-mining/

And more broadly.
www.redbooks.ibm.com/redbooks/pdfs/gg243376.pdf is a fair bit of reading if i recall, but more reading the better.
Very old, but still informative, they made us watch this in 1st year college, i find it easier to learn if i have something to visualize.
http://www.youtube.com/watch?v=xIuBmOufbls

Hope i've helped....
 
1 members found this post helpful.
Old 05-03-2012, 04:47 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by 0men View Post
Wireshark is what your after. Tcpdump is alright too, but Wireshark has a nice GUI.
Given servers usually are headless, risk should be minimized and resources should be spent wisely it IMHO should be the other way around: use tcpdump (or Wiresharks command line equivalent rawshark) for just capturing packets on the server and Wireshark, or any other network traffic analysis tool, on the analysis workstation.


Quote:
Originally Posted by gr0undzer0 View Post
I'd like to find a monitoring tool that will let me view packets, connection attempts from outside, attacks
First I'd like to add that proper hardening, in your case of the host and virtualization guest, should be aimed at reducing exposure and therefore risks. That should make regular auditing more efficient and less effort and time needed for monitoring. If you're only after logging network connections then you can use firewall rules with "-j LOG" filters, capturing packets I commented on above, and active traffic classification, possibly combined with packet capture, you can do with an IDS like Snort, Prelude or Suricata. I can't emphasize enough that proper hardening, preferably prior to exposing the server, is key.
 
1 members found this post helpful.
Old 05-03-2012, 05:15 AM   #4
anon079
Member
 
Registered: Apr 2012
Location: Alexandria, VA
Distribution: Fedora
Posts: 46

Original Poster
Rep: Reputation: 1
unSpawn,0men,

Thank you for taking the time to respond. Your answers were both really helpful. I'll start having fun with these tools when I get home from work today. My Xen VM server is at home not at work unfortunately. Ah well you have to start somewhere.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
System activity monitoring tools i.you Linux - Software 4 02-10-2010 09:49 AM
network monitoring tools bandwidth beepee Linux - Networking 2 11-03-2006 06:13 AM
Network Monitoring Tools Ahmad Gurchani Linux - Networking 1 12-16-2005 05:04 PM
The best Network monitoring tools freelinuxcpp Linux - Networking 5 04-20-2004 07:30 PM
network monitoring tools jimieee Linux - Software 2 09-25-2003 07:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration