ROOK is multi-session based Intrusion Detection System (IDS). ROOK can recognize correlations between sessions (TCP, UDP and ICMP sessions) to detect network security events.
Be the first to post a text review of ROOK. Rate and review a project by clicking thumbs up or thumbs down in the right column.
2009-03-11 mizutani <mizutani@sfc.wide.ad.jp> ROOK 0.1.2 Release - changed analyze mode option (--analyze.ex_port > --analyze.aggr_port) - added output tcpdump packet count & time span in analyze mode - changed analyze mode output directory name - fixed some bug in HTTP decoding module 2009-01-20 mizutani <mizutani@sfc.wide.ad.jp> ROOK 0.1.1 Release - fixed pthraed compile option in Makefile.am - fixed HTTP de-chunk routine - enabled zlib option to decompress HTTP gzip stream by default 2008-12-30 mizutani <mizutani@sfc.wide.ad.jp> ROOK 0.1 Release 2006-03-31 mizutani <mizutani@sfc.wide.ad.jp> Initialized Project
2009-01-20 mizutani <mizutani@sfc.wide.ad.jp> ROOK 0.1.1 Release - fixed pthraed compile option in Makefile.am - fixed HTTP de-chunk routine - enabled zlib option to decompress HTTP gzip stream by default
Be the first person to add a text review.
Copyright © 2009 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?