
IDS Reporting
Solutions in this chapter:
■
Session/Flow Logging with Snort
■
Session/Flow Logging with Argus
■
Can You Determine When a DDoS/DoS
Attack Is Occurring?
■
Using Snort for Bandwidth Monitoring
■
Using Bro to Log and Capture Application-
Level Protocols
■
Tracking Users’ Web Activities with Bro
■
Using Bro to Gather DNS and Web Traffic
Data
■
Using Bro for Blackholing Traffic to
Malware-Infested Domains
■
Using Bro to Identify Top E-Mail
Senders/Receivers
Chapter 2
37
344_Sec_Log_02.qxd 12/22/05 9:17 AM Page 37