psad - iptables log message analyzer

psad is a collection of three lightweight system daemons (two main daemons and one helper daemon) that run on Linux machines and analyze iptables log messages to detect port scans and other suspicious traffic. psad incorporates many signatures from the snort intrusion detection system to detect probes for various backdoor programs and advanced port scans (fin, null, Xmas) which are easily leveraged against a machine via nmap.

When combined with fwsnort, psad is capable of detecting approximately 75% of all snort rules, including those that inspect the application portion of ip packets. In addition, psad makes use of packet ttl, tos, ip id, and tcp window sizes to passively fingerprint remote operating systems from which scans originate. For more information see the complete list of features offered by psad.


Post new comment

  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <h1> <quote> <img>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.