Program will be responsible for analyzing these pcap files and raising an alarm if certain attacks are detected.
Types of alarm: – Anomaly detection: Count packets and sizes
– Spoofed packets: Detect packets with clearly spoofed addresses
– Unauthorized servers: Detect LAN-based servers
– Known malicious hosts: Detect DNS queries for malware domains
– Network scanning: Detect scans of the network
– IIS worms: Detect the presence of famous worms
– NTP reflection DDoS: Detect amplified denial-of-service attacks