From: Tony Kwok (sykwok8@yahoo.com)
Date: Mon Feb 24 2003 - 12:14:02 GMT-3
Dear all,
I have the following case. Pls suggest the solution.
Supposing that one of my network interface is
attacking by ICMP and I would like to pick those guys
out by knowing their address. In addition, is there
any method to identity which one is the most frequency
attack to this interface?
In my idea, I think the Netflow will be suitable
solution. But I find netflow cannot show up the path
for the ICMP and also it need to export the data out
to other server. Pls correct me if I have any
overlook. Thx.
Regards,
Tony
This archive was generated by hypermail 2.1.4 : Sat Mar 01 2003 - 11:06:33 GMT-3