looking for ideas...

poncenby smythe smythe at poncenby.plus.com
Wed Nov 15 17:41:07 EST 2006


List,

Does anyone know how to get the top 10 or just top IP which initiates 
the most meaningful* connections?

By meaningful I mean flows that can be programmatically determined to be 
human/scheduled events with reasonable payloads and meaning, aiming to 
eliminate the IPs which repeatedly scan and could conceivably be the top 
flow initiator.

Hope it makes sense,

poncenby



More information about the argus mailing list