Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 2002

IIS Informant: Analyzing Firewalls Logs for Infected Systems

RSS
Subscribe to Windows Web Solutions | See More Firewalls Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Our firewall logs show a lot of activity, but we don't have any way to analyze information about attacks—all we have are the IP addresses that launched the attacks. We'd like to advise the ISPs that own the IP addresses in our logs that they have infected systems. Do you know of a program that can scan our logs and alert us or the ISPs about infected systems?

Your situation is a serious problem that raises ethical concerns. How much responsibility do server administrators have when it comes to cleaning up other people's messes? In these uncertain times, you can make a sound argument that digital ecology (as I call it) is important because intruders can use unprotected servers as launching platforms for attacks against critical systems in our infrastructures.

The SANS Institute is on the cutting edge of addressing this concern. The institute recently helped create the Cyber Defense Initiative, which includes the Distributed Intrusion Detection System (aka DShield). This SANS Institute­sponsored project lets you submit firewall or IDS logs for processing. You can review the results online and sign up for the FightBack program, which alerts ISPs to infected computers on their systems. These services are free, and you can submit logs anonymously. For more information about DShield, go to http://www.dshield.org.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
CES 2009: Ballmer Announces Windows 7, Windows Live, Live Search Milestones

During his first-ever Consumer Electronics Show (CES) 2009 keynote address last night in Las Vegas, Microsoft CEO Steve Ballmer announced the pending public availability of a feature-complete Windows 7, the final version of Windows Live Essentials, and ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Where is Microsoft NetMeeting in Windows XP?

...


Related Events How IE7 & The New Extended Validation SSL Certificates Impact Your Site

Introduction to Identity Lifecycle Manager "2"

Delivering Reliable and Effective Web-Based Applications

Check out our list of Free Email Newsletters!

IIS and Web Administration eBooks Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Related IIS and Web Administration Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing