
If the firewall logs allowed activity with business partners, the firewall
can be used to supplement an IDS in determining the patterns of
activity with those partners.
You can determine if you are being targeted on a TCP port by
comparing the ratio of hits on that port to the total number of
firewall hits and then relating that ratio with the same calculated from
data at SANS.
Q: What information does a typical firewall log contain?
A: Different types of firewalls log different pieces of information about the
events they see.At a minimum, they will record a timestamp of when the
event happened, source and destination IP addresses, the network protocol ...