2000-02-07 17:20:19 +01:00
|
|
|
PortSentry is designed to detect and respond to port scans against a
|
2003-05-06 19:40:18 +02:00
|
|
|
target host in real-time. Some of the more useful features include:
|
2000-02-07 17:20:19 +01:00
|
|
|
|
|
|
|
+ Runs on TCP and UDP sockets to detect port scans against your
|
|
|
|
system. PortSentry is configurable to run on multiple sockets at the
|
|
|
|
same time so you only need to start one copy to cover dozens of
|
2003-05-06 19:40:18 +02:00
|
|
|
tripwired services.
|
2000-02-07 17:20:19 +01:00
|
|
|
+ PortSentry will react to a port scan attempt by blocking the host in
|
|
|
|
real-time. This is done through configured options of either dropping
|
|
|
|
the local route back to the attacker, using the Linux ipfwadm/ipchains
|
|
|
|
command, *BSD ipfw command, and/or dropping the attacker host IP into
|
2003-05-06 19:40:18 +02:00
|
|
|
a TCP Wrappers hosts.deny file automatically.
|
2000-02-07 17:20:19 +01:00
|
|
|
+ PortSentry has an internal state engine to remember hosts that
|
|
|
|
connected previously. This allows the setting of a trigger value to
|
2003-05-06 19:40:18 +02:00
|
|
|
prevent false alarms and detect "random" port probing.
|
2000-02-07 17:20:19 +01:00
|
|
|
+ PortSentry will report all violations to the local or remote syslog
|
|
|
|
daemons indicating the system name, time of attack, attacking host IP
|
|
|
|
and the TCP or UDP port a connection attempt was made to. When used
|
|
|
|
in conjunction with Logcheck it will provide an alert to
|
2003-05-06 19:40:18 +02:00
|
|
|
administrators through e-mail.
|
2000-02-07 17:20:19 +01:00
|
|
|
+ Once a scan is detected your system will turn into a blackhole and
|
2003-05-06 19:40:18 +02:00
|
|
|
disappear from the attacker. This feature stops most attacks cold.
|