Hello - I am looking for tools that I can setup to monitor network traffic, ideally passively, which will try to detect and alert me to attacks or suspicious activity _originating_ within my networks. I already have several tools setup that detect activity targetting my networks, and now want to make certain that knowbody launches anything from within the address space that I am responsible for. For reference, I am working with several /18, /19, and various smaller network blocks, often times multi-homed through several geographically diverse methods. Suggestions and references would be greatly appreciated. Thanks in advance - Marc
This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:58:48 PDT