Analyzing network data with appliance router
Patton Echols
p.echols at comcast.net
Sun Jun 12 22:47:02 UTC 2011
Greetings all,
I am looking for ways to analyze the traffic through my home network.
The tools that I seen mentioned as I google all seem to need to run on
the router. This makes sense to me. After all, where better to access
the traffic. I am wondering whether there are tools that can moniter
traffic within the LAN and / or to and from the WAN, but do it from my
desktop machine within the LAN.
Here is what I am trying to do:
I have been reading about concerns of Botnets and a recent article that
suggested that nearly 20% or windows machines are infected. I have to
support several windows machines in our network. We have antivirus and
updates applied as soon as available, but I would like to have a way to
ID a box that gets infected. One suggested method is to watch their
traffic. If a windows box has spikes in network activity, starts port
scanning, or doing other obnoxious activity, then you know you have work
to do.
The logging function of my appliance router is fairly minimal. It
records the outgoing IP and protocol, but not the port or the time.
Also, it seems to be pretty limited as to how much it saves. I'd prefer
to not have to set up my own router if not necessary.
Any thoughts?
-- PE
More information about the ubuntu-users
mailing list