Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Introduction to IPAudit
Paul Asadoorian

IPAudit is a handy tool that will allow you to analyze all packets entering and leaving your network. It listens to a network device in promiscuous mode, just as an IDS sensor would, and provides details on hosts, ports, and protocols. It can be used to monitor bandwidth, connection pairs, detect compromises, discover botnets, and see whos scanning your network. When compared to similar tools, such as Cisco System's Netflow it has many advantages (see the SecurityFocus articles on Netflow, part 1 and part 2). It is easier to setup than Netflow, and if you install it on your existing IDS sensors, there is no extra hardware to purchase. Since it captures traffic from a span port, it does not require that you modify the configuration of your networking equipment, or poke holes in firewalls for Netflow data.

Comments Mode:
Introduction to IPAudit 2006-02-10
Anonymous (1 replies)
Re: Introduction to IPAudit 2006-02-16
Veerendra
Introduction to IPAudit 2006-02-27
Anantha K (1 replies)
Re: Introduction to IPAudit 2006-03-01
Veerendra (1 replies)
Re: Re: Introduction to IPAudit 2006-03-03
Anantha K (1 replies)
Introduction to IPAudit 2006-07-20
Anonymous
Introduction to IPAudit (alternative for Probe one ?) 2006-07-24
Anonymous
This looks like a low-cost alternative for those people who dont't need all the extensive reporting capabilities of commercial network analyser like Probe one.

Altough it is nog clear to me if this tool is also capable of zooming into specific network segments like the probe can.

Jerry.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1842/628#628







 

Privacy Statement
Copyright 2007, SecurityFocus