etch  ] [  etch-m68k  ] [  lenny  ] [  squeeze  ] [  sid  ]
[ Source: psad  ]

Package: psad (2.1.5-1)

The Port Scan Attack Detector

PSAD is a collection of four lightweight system daemons written in Perl and in C that is designed to work with Linux firewalling code (iptables in the 2.4.x kernels, and ipchains in the 2.2.x kernels) to detect port scans. It features a set of highly configurable danger thresholds (with sensible defaults provided), verbose alert messages that include the source, destination, scanned port range, begin and end times, tcp flags and corresponding nmap options (Linux 2.4.x kernels only), reverse DNS info, email alerting, and automatic blocking of offending ip addresses via dynamic configuration of ipchains/iptables firewall rulesets.

In addition, for the 2.4.x kernels psad incorporates many of the tcp signatures included in Snort to detect highly suspect scans for:

 * various backdoor programs (e.g. EvilFTP, GirlFriend, SubSeven)
 * DDoS tools (mstream, shaft)
 * advanced port scans (syn, fin, xmas) such as those made with nmap
.

Tags: System Administration: Monitoring, User Interface: Daemon, Networking: Firewall, Server, Role: Program, Security: Firewall, Intrusion Detection, Purpose: Checking

Other Packages Related to psad

  • depends
  • recommends
  • suggests
  • sug: fwsnort
    Snort-to-iptables rule translator

Download psad

Download for all available architectures
Architecture Package Size Installed Size Files
alpha 178.4 kB760 kB [list of files]
amd64 179.1 kB756 kB [list of files]
armel 178.4 kB752 kB [list of files]
avr32 (unofficial port) 175.3 kB748 kB [list of files]
hppa 177.7 kB756 kB [list of files]
hurd-i386 175.6 kB752 kB [list of files]
i386 174.7 kB752 kB [list of files]
ia64 180.4 kB776 kB [list of files]
kfreebsd-amd64 176.4 kB688 kB [list of files]
kfreebsd-i386 175.3 kB680 kB [list of files]
m68k (unofficial port) 176.4 kB676 kB [list of files]
mips 177.3 kB760 kB [list of files]
mipsel 177.3 kB760 kB [list of files]
powerpc 177.1 kB756 kB [list of files]
s390 176.9 kB752 kB [list of files]
sparc 177.7 kB752 kB [list of files]