Ourmon is a network monitoring and anomaly detection system and displays the data for multiple BPF expressions via RRDTOOL-based graphs. It also helps the user identify various kinds of network anomalies including IRC botnets, TCP and UDP scanners.
Be the first to post a text review of ourmon. Rate and review a project by clicking thumbs up or thumbs down in the right column.
A new release of the ourmon network monitoring and anomaly detection tool is available. New features include support for DNS statistics and a DNS-based blacklist, IP blacklists, improved event log support for security events, improved UDP port signature attributes to help identify scanners and p2p-using hosts, and an experimental threaded probe. Although it is late to mention this, there is a book out with 4 chapters on ourmon. The chapters are still relevant to this release. See Botnets: The Killer Web App, at http://www.syngress.com/catalog/?pid=4270 on the web. Further reading on ourmon and its new features may be found at: http://ourmon.cat.pdx.edu/ourmon/info.html
Be the first person to add a text review.
Copyright © 2009 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?
Thanks for your review!
Get credit for your review by logging in via OpenID. Click your account provider: