MRTG for intrusion detection with IIS 6
The Multi Router Traffic Grapher (MRTG) is a simple cross-platform tool that administrators have used for years to monitor network traffic loads. The concept is simple: it queries SNMP counters and creates HTML pages with live network graphs showing bytes coming in and bytes going out. MRTG can show much more than in and out traffic, it can graph any SNMP counter. Microsoft has a web site that demonstrates some of the many SNMP counters available on a Windows 2003 server.
But MRTG is also a very effective intrusion detection tool. The concept is simple: attacks often produce some kind of anomalous pattern and human brains are well-equipped to spot anomalous patterns, given some way to visualize those patterns. The MRTG does just that -- it gives you the big picture of your network traffic and it also slices it into different views, allowing you to see any counter trends for the last week, month, or year.
[ Read more ]
- Article: An Overview of Issues in Testing Intrusion Detection Systems (23 July 2003)
- Article: Intrusion detection (11 June 2003)
- Article: Monitored Intrusion Detection Systems (1 September 2002)
- Article: An Introduction to Snort (7 June 2002)
- Article: Know Your Enemy: Honeynets (11 April 2002)
- Article: Know Your Enemy: Passive Fingerprinting (11 April 2002)
- Article: Know Your Enemy: Worms at War (11 April 2002)
- Article: Know Your Enemy: Motives (11 April 2002)
- Article: Know Your Enemy: A Forensics Analysis (11 April 2002)
- Article: Know Your Enemy: III (11 April 2002)
- Article: Know Your Enemy: II (11 April 2002)
- Article: Know Your Enemy (11 April 2002)
- Article: Structural versus Operational Intrusion Detection (8 April 2002)
- Article: Interpreting Network Traffic: A Network Intrusion Detector's Look At Suspicious Events (4 April 2002)
- Article: Network Intrusion Detection of Third Party Effects (4 April 2002)
- Article: Information Warfare: When Intrusion Detection Isn't Enough (1 April 2002)
Reading our newsletter every Monday will keep you up-to-date with security news.
Receive a daily digest of the latest security news.