new security feature
Posted: Sat Nov 08, 2003 12:21 am
This is the best!
You might or might not know about my script that logs stuff and "autodetects" potential trouble and sets off alarms, and also checks rules such as IPs, well I just made it so it emails me as soon as there's an alarm and it looks like this:
A Status 2 alarm has been triggered at November 8, 2003, 12:09:05 am by IP: aaa.bbb.ccc.ddd.
Alarm text: "IP rule "aaa.bbb.ccc." matched with "aaa.bbb.ccc.ddd""
http://scada.iceteks.com - IceTeks Supervisory Control And Data Acquisition
.
Alarms range from status 1 to 5, 1 is something very minor. For example if I suspect someone doing something, I'll set stealth tracking/alarming on the user but not more then that, and just take a closer look at activity from any alarms that pop up, these are usually cleared off fast enough and disregarded as they are usually just false alarms and not much worry. The user in question is treated like any other user as for permissions and stuff. But a status 5 alarm is someone trying to guess passwords and such. Pround to say I only got like 3-4 of these, not more. Really, only alarms I've been getting lately are from this one IP I blocked ages ago. It is believed to be some chick at bbt who is a real B17ch.
With this new emailing system, I can forward the alarms to the intruder when I know for sure it's them.
Archived topic from Iceteks, old topic ID:1578, old post ID:13219
You might or might not know about my script that logs stuff and "autodetects" potential trouble and sets off alarms, and also checks rules such as IPs, well I just made it so it emails me as soon as there's an alarm and it looks like this:
A Status 2 alarm has been triggered at November 8, 2003, 12:09:05 am by IP: aaa.bbb.ccc.ddd.
Alarm text: "IP rule "aaa.bbb.ccc." matched with "aaa.bbb.ccc.ddd""
http://scada.iceteks.com - IceTeks Supervisory Control And Data Acquisition
.
Alarms range from status 1 to 5, 1 is something very minor. For example if I suspect someone doing something, I'll set stealth tracking/alarming on the user but not more then that, and just take a closer look at activity from any alarms that pop up, these are usually cleared off fast enough and disregarded as they are usually just false alarms and not much worry. The user in question is treated like any other user as for permissions and stuff. But a status 5 alarm is someone trying to guess passwords and such. Pround to say I only got like 3-4 of these, not more. Really, only alarms I've been getting lately are from this one IP I blocked ages ago. It is believed to be some chick at bbt who is a real B17ch.
With this new emailing system, I can forward the alarms to the intruder when I know for sure it's them.
Archived topic from Iceteks, old topic ID:1578, old post ID:13219