scanlogd - detects and logs TCP port scans


Total views: 397 | Today, 11

Written by Pavs on December 26th, 2007                                        


scanlogd detects port scans and writes one line per scan via the syslog mechanism. If a source address sends multiple packets to different ports in a short time, the event will be logged. In order to do its job, scanlogd needs a way to obtain raw IP packets that either come to the system scanlogd is running on, or travel across a network segment that is directly connected to the system.

At least 7 different privileged or 21 non-privileged ports, or a weighted combination of those, have to be accessed with no longer than 3 seconds between the accesses to be treated as a scan. If more than 5 scans are detected within 20 seconds, that event will be logged and logging will be stopped temporarily.
Logging is done with a facility of daemon and a priority level alert.

scanlogd should be started as root since it needs access to a packet capture interface. By default, it switches to running as user scanlogd after the packet capture interface is initialized.

A look at standard log files and where it’s stored, this information can be changed from /etc/syslog.conf

2007-12-26-045457_1280x800_scrot

In the event of a port scan I will be looking at /var/log/daemon.log

2007-12-26-050021_1280x800_scrot

If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!



Thank you for reading this post. You can now Leave A Comment (0) or Leave A Trackback.



Leave a Reply

Note: Any comments are permitted only because the site owner is letting you post, and any comments will be removed for any reason at the absolute discretion of the site owner.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

.
Google
 
.

Recommended Books