IDS Statistics generated on Wed Aug 23 13:21:37 2006 SnortALog

The log begins at :Aug 21 22:33:50
The log ends at :Aug 22 09:22:08
Total of Lines in log file :6558038
Total events in table :1074179
Source IP recorded :6945
Destination IP recorded :7149
Host logger recorded :1 with 1 interface(s)
Signatures recorded :15
Classification recorded :1
Severity recorded :1
Portscan detected :0
Domains File : conf/domains
Number of domains : 267
Rules File : conf/rules
Number of referenced rules : 2067

Legend :
RED :Dangerous connection (potentially bad, further investigation needed)
GREEN :Warning connection (strange, may need further intevestigation)
BLACK :Not dangerous alert

Distribution of attack methods

%NoAttackPrioritySeverity
0.001 BLEEDING-EDGE P2P ed2k file request answer {tcp} 1high
0.001 BLEEDING-EDGE P2P Ares traffic {tcp} 1high
0.005 BLEEDING-EDGE P2P GnucDNA UDP Ultrapeer Traffic {udp} 1high
0.006 BLEEDING-EDGE P2P Gnutella TCP Ultrapeer Traffic {tcp} 1high
0.0013 BLEEDING-EDGE P2P ed2k connection to server {tcp} 1high
0.0015 BLEEDING-EDGE P2P eDonkey Search {udp} 1high
0.0015 BLEEDING-EDGE P2P Kaaza Media desktop p2pnetworking.exe Activity {udp}1high
0.0016 BLEEDING-EDGE P2P eDonkey File Status Request {tcp} 1high
0.0026 BLEEDING-EDGE P2P Ares GET {tcp} 1high
0.05554 BLEEDING-EDGE P2P LimeWire P2P Traffic {tcp} 1high
0.151618 BLEEDING-EDGE P2P Gnutella Connect {tcp} 1high
5.5960073 BLEEDING-EDGE P2P BitTorrent Traffic {tcp} 1high
8.9095556 BLEEDING-EDGE P2P Overnet Server Announce {udp} 1high
22.46241244BLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp} 1high
62.84675036BLEEDING-EDGE P2P BitTorrent peer sync {tcp} 1high

Distribution of classification method

%NoClassificationSeverity
100.001074179Potential Corporate Privacy Violation high

Distribution of event by day

DayMonthNo%Graph
21 08 19302317.97
22 08 88115682.03

Distribution of attack by hour

HourNo%Graph
0h13178512.27
1h12238611.39
2h11952611.13
3h93971 8.75
4h69816 6.50
5h55738 5.19
6h54346 5.06
7h63180 5.88
8h12603511.73
9h44373 4.13
22h72301 6.73
23h12072211.24

Attacks by hour

%NoHourAttack
0.001 6hBLEEDING-EDGE P2P Kaaza Media desktop p2pnetworking.exe Activity {udp}
0.001 4hBLEEDING-EDGE P2P eDonkey File Status Request {tcp}
0.001 8hBLEEDING-EDGE P2P Kaaza Media desktop p2pnetworking.exe Activity {udp}
0.001 3hBLEEDING-EDGE P2P ed2k file request answer {tcp}
0.001 3hBLEEDING-EDGE P2P Kaaza Media desktop p2pnetworking.exe Activity {udp}
0.001 22hBLEEDING-EDGE P2P eDonkey Search {udp}
0.001 5hBLEEDING-EDGE P2P Kaaza Media desktop p2pnetworking.exe Activity {udp}
0.001 22hBLEEDING-EDGE P2P ed2k connection to server {tcp}
0.001 22hBLEEDING-EDGE P2P Gnutella TCP Ultrapeer Traffic {tcp}
0.001 4hBLEEDING-EDGE P2P ed2k connection to server {tcp}
0.001 23hBLEEDING-EDGE P2P ed2k connection to server {tcp}
0.001 23hBLEEDING-EDGE P2P Gnutella TCP Ultrapeer Traffic {tcp}
0.001 8hBLEEDING-EDGE P2P eDonkey Search {udp}
0.001 3hBLEEDING-EDGE P2P eDonkey Search {udp}
0.002 8hBLEEDING-EDGE P2P Gnutella TCP Ultrapeer Traffic {tcp}
0.002 23hBLEEDING-EDGE P2P eDonkey Search {udp}
0.002 7hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.002 7hBLEEDING-EDGE P2P ed2k connection to server {tcp}
0.002 6hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.002 23hBLEEDING-EDGE P2P eDonkey File Status Request {tcp}
0.002 1hBLEEDING-EDGE P2P Kaaza Media desktop p2pnetworking.exe Activity {udp}
0.002 4hBLEEDING-EDGE P2P eDonkey Search {udp}
0.002 7hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.002 2hBLEEDING-EDGE P2P Gnutella TCP Ultrapeer Traffic {tcp}
0.002 6hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.002 7hBLEEDING-EDGE P2P eDonkey Search {udp}
0.002 6hBLEEDING-EDGE P2P eDonkey Search {udp}
0.003 1hBLEEDING-EDGE P2P ed2k connection to server {tcp}
0.003 9hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.003 4hBLEEDING-EDGE P2P Kaaza Media desktop p2pnetworking.exe Activity {udp}
0.003 2hBLEEDING-EDGE P2P ed2k connection to server {tcp}
0.004 4hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.004 23hBLEEDING-EDGE P2P Kaaza Media desktop p2pnetworking.exe Activity {udp}
0.004 2hBLEEDING-EDGE P2P eDonkey Search {udp}
0.005 8hBLEEDING-EDGE P2P GnucDNA UDP Ultrapeer Traffic {udp}
0.005 4hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.005 1hBLEEDING-EDGE P2P eDonkey File Status Request {tcp}
0.005 2hBLEEDING-EDGE P2P eDonkey File Status Request {tcp}
0.0026 8hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.0026 9hBLEEDING-EDGE P2P Ares GET {tcp}
0.0033 9hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.0042 3hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.0156 22hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.0173 1hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.01114 3hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.01132 2hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.01135 23hBLEEDING-EDGE P2P LimeWire P2P Traffic {tcp}
0.01137 1hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.02211 22hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.02258 8hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.03274 2hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.04393 23hBLEEDING-EDGE P2P Gnutella Connect {tcp}
0.121253 9hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.151619 22hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.212258 7hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.242603 9hBLEEDING-EDGE P2P Overnet Server Announce {udp}
0.242628 8hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.373970 22hBLEEDING-EDGE P2P Overnet Server Announce {udp}
0.394154 6hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.555899 23hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.566057 4hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.596335 1hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.616564 4hBLEEDING-EDGE P2P Overnet Server Announce {udp}
0.636814 2hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.646841 23hBLEEDING-EDGE P2P Overnet Server Announce {udp}
0.707491 5hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.727766 6hBLEEDING-EDGE P2P Overnet Server Announce {udp}
0.737822 2hBLEEDING-EDGE P2P Overnet Server Announce {udp}
0.747911 3hBLEEDING-EDGE P2P Overnet Server Announce {udp}
0.788405 5hBLEEDING-EDGE P2P Overnet Server Announce {udp}
0.818690 3hBLEEDING-EDGE P2P BitTorrent Traffic {tcp}
0.869191 9hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
0.929856 4hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
0.9310015 8hBLEEDING-EDGE P2P Overnet Server Announce {udp}
0.9610318 3hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
0.9710423 5hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
1.0411188 1hBLEEDING-EDGE P2P Overnet Server Announce {udp}
1.2012895 6hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
1.2313254 7hBLEEDING-EDGE P2P Overnet Server Announce {udp}
1.5516637 7hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
1.8419797 22hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
1.8820171 8hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
2.2023639 2hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
2.7429418 5hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
2.7529524 6hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
2.8931023 7hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
2.9031185 1hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
2.9131264 9hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
3.9141969 23hBLEEDING-EDGE P2P Direct Connect Traffic (client-server) {tcp}
4.3446645 22hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
4.4147323 4hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
6.1065475 23hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
6.2366893 3hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
6.8473458 1hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
7.5280831 2hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}
8.6592928 8hBLEEDING-EDGE P2P BitTorrent peer sync {tcp}

Distribution of event by protocols

%NoProtocols
91.10978588tcp
8.9095591 udp



Main Stats
IP Src
IP Dst
Protocols
Hour
Days
Services
Source Log

IDS/IPS Stats
Attack by Src
Attack by Dst
Attack by Src and Dst
Attacks
Alert Severity
Alert Classification
Attacks by Services
Attacks by Hours

 
 
   
 
 
powered by SnortALog
© SnortALog 2000-2005