looking for ideas...
poncenby smythe
smythe at poncenby.plus.com
Wed Nov 15 17:41:07 EST 2006
List,
Does anyone know how to get the top 10 or just top IP which initiates
the most meaningful* connections?
By meaningful I mean flows that can be programmatically determined to be
human/scheduled events with reasonable payloads and meaning, aiming to
eliminate the IPs which repeatedly scan and could conceivably be the top
flow initiator.
Hope it makes sense,
poncenby
More information about the argus
mailing list