Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Introduction to IPAudit
Paul Asadoorian

IPAudit is a handy tool that will allow you to analyze all packets entering and leaving your network. It listens to a network device in promiscuous mode, just as an IDS sensor would, and provides details on hosts, ports, and protocols. It can be used to monitor bandwidth, connection pairs, detect compromises, discover botnets, and see whos scanning your network. When compared to similar tools, such as Cisco System's Netflow it has many advantages (see the SecurityFocus articles on Netflow, part 1 and part 2). It is easier to setup than Netflow, and if you install it on your existing IDS sensors, there is no extra hardware to purchase. Since it captures traffic from a span port, it does not require that you modify the configuration of your networking equipment, or poke holes in firewalls for Netflow data.

Comments Mode:
Introduction to IPAudit 2006-02-10
Anonymous (1 replies)
Re: Introduction to IPAudit 2006-02-16
Veerendra
Introduction to IPAudit 2006-02-27
Anantha K (1 replies)
Re: Introduction to IPAudit 2006-03-01
Veerendra (1 replies)
Re: Re: Introduction to IPAudit 2006-03-03
Anantha K (1 replies)
Re: Re: Re: Introduction to IPAudit 2006-09-15
ng1p
I had the same problem. It was becouse I was running a 64 bit linux version of perl. Go to the ipaudit forum for the full answer and fix.

http://sourceforge.net/forum/forum.php?thread_id=1570947&forum_id=59302

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1842/683#683
Introduction to IPAudit 2006-07-20
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus