Americas

  • United States

Internet storm activity

Opinion
Oct 06, 20031 min
Intrusion Detection SoftwareNetwork SecurityNetworking

What is the Internet Storm Center? How can you contribute firewall logs to its network security monitoring process?

What is the Internet Storm Center? How can we contribute firewall logs to its network security monitoring process?

The Internet Storm Center grew out of the SANS Institute’s Consensus Incident Database project, which began monitoring global Internet traffic in November 2000. The center is a free service that collects intrusion-detection information from the Internet to identify new attacks and provide information about the types of attacks being mounted against Internet resources.

At www.incidents.org you can find lists of the top 10 ports being attacked, ongoing attack trends and other security information, including an online ticker showing current trends.

To submit your traffic logs to the system, go to www.dshield.org/howto.php. Automated client software is provided for several Windows and Linux firewalls. The client software automates the process of finding the appropriate portion of your firewall logs and e-mailing the information to Dshield.

Logs also can be submitted through a Web form interface or directly through some firewall hardware equipment. Registering with Dshield is encouraged but not required to participate in the reporting service.