| Detecting suspicious network traffic with psad |
| Source: Newsforge - Posted by Pax Dickinson | ||
|
Once you've met the requirements, install psad using the installation script included in the product's download. Just run the script install.pl and answer a few simple questions about your system's configuration. If you need to make future changes to psad's configuration, you can edit its configuration file, /etc/psad/psad.conf. When you start psad with the command /etc/rc.d/psad start, you actually start psad and its two helper daemons, kmsgsd and psadwatchd. kmsgsd parses out all of the iptables-related messages that the kernel receives and sends them to psad's data file /var/log/psad/fwdata. The psadwatchd daemon runs every five seconds to make sure that both psad and kmsgsd are running. If they are not, it restarts them and sends an email alerting the system administrator to this fact. Read this full article at Newsforge
Only registered users can write comments. Powered by AkoComment! |
||