Detect high numbers of outgoing connections per user. Maybe use Snort?

Concluído Postado Feb 13, 2012 Pago na entrega
Concluído Pago na entrega

I'd like to detect abusive network traffic outgoing from my server (caused by different users on the server, maybe they're infected by a virus).

I'd like a solution that I can install as root on the server and that'll alert me if the number of outgoing connections per user (each has a unique private IP) per 1-minute time interval exceeds some threshold. Alert me simply by calling an HTTP POST webservice.

This needs to work on Ubuntu 10.04 LTS

In your bid, please specify what path you would take to solve this. Use Snort, or some other existing package? Or build something custom with iptables?

I'll also need a script to install/deploy the solution on the server.

Engenharia Linux Gestão de projetos Instalação de Script Shell Script Arquitetura de software Teste de Software Administrador do Sistema

ID do Projeto: #2711343

Sobre o projeto

4 propostas Projeto remoto Ativo em Feb 28, 2012

Concedido a:

kobor

See private message.

$42.5 USD em 22 dias
(75 Comentários)
4.9

4 freelancers estão ofertando em média $216 nesse trabalho

tiborveres

See private message.

$250.75 USD in 22 dias
(25 Comentários)
5.6
njcole

See private message.

$150 USD in 22 dias
(12 Comentários)
5.4
klarakarl

See private message.

$420.75 USD in 22 dias
(17 Comentários)
4.8