Skip to content

Series of packets identification capabilities #4

@ilyaglow

Description

@ilyaglow

Marking of a single packet is not enough sometimes to detect scanners like nmap and some types of attacks.

The badcapt should use some kind of caching mechanisms for a particular source IP-address to process through all packets the host sent.

Caching libraries to consider:

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions