RE: Network abuse report

From: Ronald I. Nutter (ronald_nutter_at_georgetowncollege.edu)
Date: 05/27/05

  • Next message: Smith, Ryan: "RE: help , scripting for security"
    Date: Fri, 27 May 2005 08:36:38 -0400
    To: "Diego Kellner" <dkepler@gmail.com>, <security-basics@securityfocus.com>
    
    

    Look at dshield.org. They have a program available that can
    automatically analyze the logs for most firewalls and automate some of
    the process for you.

    Ron

    --------------------------------------------------------------------
    Ron Nutter ron_nutter@georgetowncollege.edu
    Network Infrastructure & Security Manager
    Information Technology Services (502)863-7002
    Georgetown College
    Georgetown, KY 40324-1696
    --------------------------------------------------------------------
     

    -----Original Message-----
    From: Diego Kellner [mailto:dkepler@gmail.com]
    Sent: Thursday, May 26, 2005 11:02 AM
    To: security-basics@securityfocus.com
    Subject: Network abuse report

    Hi, I am now encharged of analyzing firewall logs in my company, and I'm
    beggining frequent port scanning from certain IPs (most of them in
    Asia). I know it might not change a thing, but I'd like to report this
    IPs to their respective ISPs. Anyone has (or knows of a web site that's
    got) Network Abuse Mail Templates I could use? Regards, Diego


  • Next message: Smith, Ryan: "RE: help , scripting for security"

    Relevant Pages

    • RE: [fw-wiz] Firewalls v. Router ACLs
      ... people to take in consideration in network design and layout. ... here and the old firewalls list often emphasized an approach that avoided ... The logging alert features alone turn this layer into a IDS as ... > An appropriately sized router will not have any performance problems. ...
      (Firewall-Wizards)
    • [fw-wiz] IDS/IPS and LOGS
      ... nasty behavior is happening on your network (where your network is ... easily turn your IPS into a big denial of service attack. ... My guess is that most of the Worlds firewalls and IDS/IPS only have half ... I noticed that there is a big emphasis on log parsing while there should ...
      (Firewall-Wizards)
    • Re: Establish persistant outbound connection for covert application
      ... which firewalls are running etc.) and then communicate its ... the actual network layer. ... They do have 2 network interfaces in case I want to chain them between a PC ... They also have a wireless interface so I can hook into the machine if I am ...
      (Security-Basics)
    • Re: Log file full of security problems!
      ... having with my small peer-to-peer network. ... Primary User Name: Mark ... Primary Logon ID: ... Disable the logging for the time being; Clear the logs or copy them to ...
      (microsoft.public.windowsxp.network_web)
    • Re: Going meta (was RE: [fw-wiz] Ok, so now we have a firewall...)
      ... but today's firewalls let too much stuff back ... > why people feel they need to compromise. ... Last spring we completely re-engineered the network for a large school ... All these segments are set up on separate VLANs and communicate with each ...
      (Firewall-Wizards)