
passed throughout other security teams for coordination with anti-
virus deletes and captures of the virus/Trojan.
As with most IDS work, monitoring network resources is a
privileged task. However, as hopefully has been seen with the Bro
data, this is considered privacy data at some organizations.
Q: What are some other tools in the open source community similar to Argus
and Snort’s Keepstats directive:
A: SANCP (Security Analyst Network Connection Profiler) is a tool in devel-
opment that looks promising: http://www.metre.net/sancp.html. Netstate is
another tools that is being developed at Sandia National Labs: http://net-
state.ca.sandia.gov/. A v