Data Mining for PIX Firewall Logs

From: Carey Heck (carey.heck_at_gmail.com)
Date: 02/09/05

  • Next message: Tim: "Re: Mapping Class A network ( any easy trick?)"
    Date: Wed, 9 Feb 2005 17:08:59 -0500
    To: pen-test@securityfocus.com, bugtraq@securityfocus.com
    
    

    Hi folks. I love the ability in the Checkpoint firewall logging
    applet that allows me to load up any former saved log file, and filter
    according to any criteria I set.

    Lets use an example:

    I want to show an auditor what exactly went through my firewall,
    to/from a specific DMZ host, between the hours of 1 and 3pm GMT, on
    July 8th, 2003.

    In checkpoint, if I had correctly configured my ruleset, and archived
    my log files properly, I could provide this answer within 30 minutes.

    Fast forward to my current company, which went with a Cisco PIX
    solution based on the up front cost. I can log all the connections to
    my heart content, but boy mining the data to help show what happened
    in my above example has been tiresome at best.

    Can anyone here please suggest to me some type of logging and more
    relevantly, a data mining product that can help me achieve this end?

    Currently I am logging all my PIX traffic to a host running Kiwi
    syslog daemon, which archives each days logs into a separate folder in
    the dated logs directory, creating a new directory named for each date
    in the year.

    I am looking for a less clunky solution.

    Any help is GREATLY appreciated.

    Thanks!

    -- 
    Carey
    

  • Next message: Tim: "Re: Mapping Class A network ( any easy trick?)"

    Relevant Pages

    • Re: Logging components?
      ... I think Logging is pretty much individual, so that usualy everyone has their ... {Write Logged exception into the Log file? ... {Write exception with a short string description into the Global App Log ... > By logging components, I specifically DON'T MEAN components for catching ...
      (borland.public.delphi.thirdpartytools.general)
    • Re: Phantom /var full messages
      ... if you could isolate it to just snort or just MySQL. ... without restarting the program that's logging to them. ... compresses the current log file into a new file, ...
      (freebsd-questions)
    • Re: Annoying 1202 errors
      ... Enabling this logging tracks all changes and settings applied to the machine ... Name: UserEnvDebugLevel ... I recommend that you remove any existing log file and then use gpupdate ... feature GUEST. ...
      (microsoft.public.win2000.group_policy)
    • Re: Theodore Adorno, a prophet of data systems design
      ... >> Can you translate the above into English please? ... > at compile time or runtime, up to you) what level of logging you wish. ... >> a single log file from multiple threads for anyone with even a beginner's ... > Actually, I can't guarantee that it will work in a multithreaded program, ...
      (comp.programming)
    • RE: Unable to SEND faxes
      ... to verify that your modem/device is on the Microsoft Hardware Compatibility ... You could also turn on Session logging and see if that reveals any thing: ... 102,400 - Maximum size of a single log file, in bytes. ... incoming session logs folder ...
      (microsoft.public.windows.server.sbs)