From: Holt Grendal (holtor@yahoo.com)
Date: Wed Feb 05 2003 - 19:01:02 PST
Hi all,
It is my intention to use netflow and cflowd to try to
track DoS attacks.
It makes sense to me that there must be some functionality
out there to examine the flows and traffic and if a certain IP
is receiving a large amount of traffic/flows (which perhaps the
operator can specify a threshold) that the system could let you
know.
Does anyone know how and if this is possible?
Thank you,
Holt G.
__________________________________________________
Do you Yahoo!?
Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
http://mailplus.yahoo.com
_______________________________________________
Cflowd mailing list
Cflowd@caida.org
http://login.caida.org/mailman/listinfo/cflowd
This archive was generated by hypermail 2.1.4 : Wed Feb 05 2003 - 19:12:03 PST