Re: Monitoring for breakins

From: James Riden (james.riden@ed.ac.uk)
Date: 07/18/02


From: James Riden <james.riden@ed.ac.uk>
Date: 18 Jul 2002 15:32:54 +0100

Thomas Gagné <tgagne@ameritech.net> writes:

> Is there a FAQ that visits this concept?
>
> I've recently built a reverse proxy server that'll live inside a DMZ,
> and now I need to monitor attempts to break-in.
>
> What's everyone else using?

snort and tripwire are helpful. I think there's a program called
swatch that will monitor logs as well.

cheers,
 Jamie

-- 
James Riden / james.riden@ed.ac.uk / jamesr@europe.com
MSc student, Dept. of Informatics, University of Edinburgh.