<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: argus - Auditing Network Activity - Performance &#038; Status Monitoring</title>
	<atom:link href="http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Thu, 04 Dec 2008 20:42:52 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-108211</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Thu, 07 Feb 2008 07:56:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-108211</guid>
		<description>Really helpful stuff for an admin. 

Could this be somehow remotely installed into a server so you can monitor everything going over a network?</description>
		<content:encoded><![CDATA[<p>Really helpful stuff for an admin. </p>
<p>Could this be somehow remotely installed into a server so you can monitor everything going over a network?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mumble</title>
		<link>http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-104403</link>
		<dc:creator>mumble</dc:creator>
		<pubDate>Tue, 29 Jan 2008 14:53:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-104403</guid>
		<description>In general, as a systems admin, I'm used to being in charge of the availability part. In the real world (of not penetration testing) the causes of downtime are normally things like dead PSUs, bad switches, dead NICs, bad software updates, database corruption, bad juju, phase of the moon, upstream routing BS.....

This is a very useful tool for looking at bandwidth, flows, traffic/responsiveness, etc. I usually see that work as being mora a sysad's job that a SA's job. Given where I'm coming from, that's reasonably sane.....</description>
		<content:encoded><![CDATA[<p>In general, as a systems admin, I&#8217;m used to being in charge of the availability part. In the real world (of not penetration testing) the causes of downtime are normally things like dead PSUs, bad switches, dead NICs, bad software updates, database corruption, bad juju, phase of the moon, upstream routing BS&#8230;..</p>
<p>This is a very useful tool for looking at bandwidth, flows, traffic/responsiveness, etc. I usually see that work as being mora a sysad&#8217;s job that a SA&#8217;s job. Given where I&#8217;m coming from, that&#8217;s reasonably sane&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-104383</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Tue, 29 Jan 2008 13:59:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-104383</guid>
		<description>From a security POV, there are three main aspects for security, Confidentiality, Integrity and Availability. This tool can help with all but particularly the latter two.
Security is not all about penetration testing!</description>
		<content:encoded><![CDATA[<p>From a security POV, there are three main aspects for security, Confidentiality, Integrity and Availability. This tool can help with all but particularly the latter two.<br />
Security is not all about penetration testing!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-103594</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Sun, 27 Jan 2008 18:48:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-103594</guid>
		<description>Well as a sys admin you should know if someone untoward goes down it's you they are gonna ask to prove/disprove it from a technical standpoint.

If you don't have records you are screwed :) That's why this is in forensics category.

And networking is a fundamental part of security anyway especially from an understand point of view, on top of that from a monitoring point - you can find anomalies which can point to deeper problems, and from a intrusion response angle - records are golden. Thats why we advocate the use of syslog-ng on a separate server :)</description>
		<content:encoded><![CDATA[<p>Well as a sys admin you should know if someone untoward goes down it&#8217;s you they are gonna ask to prove/disprove it from a technical standpoint.</p>
<p>If you don&#8217;t have records you are screwed <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> That&#8217;s why this is in forensics category.</p>
<p>And networking is a fundamental part of security anyway especially from an understand point of view, on top of that from a monitoring point - you can find anomalies which can point to deeper problems, and from a intrusion response angle - records are golden. Thats why we advocate the use of syslog-ng on a separate server <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-103550</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Sun, 27 Jan 2008 17:21:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-103550</guid>
		<description>@mumble, indeed the security edge seems to be missing but rumble gives ample reply to the use of Argus. We use it to map network flow and use the logs to analyze why and when network congestion occurs. The fact that it is modest regarding record size while generating extensive data is definitely a plus.</description>
		<content:encoded><![CDATA[<p>@mumble, indeed the security edge seems to be missing but rumble gives ample reply to the use of Argus. We use it to map network flow and use the logs to analyze why and when network congestion occurs. The fact that it is modest regarding record size while generating extensive data is definitely a plus.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rumble</title>
		<link>http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-103271</link>
		<dc:creator>rumble</dc:creator>
		<pubDate>Sun, 27 Jan 2008 01:14:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-103271</guid>
		<description>argus records are cheap to store, and they can be used for a lot of security-related things: building flow records between servers, mining flows for unusual communication patterns, mining historical traffic patterns, etc. We can cram about a year's worth of all activity on our 20Mbps internet perimeter into about 20 gig or so worth of uncompressed argus logs. makes for some interesting hunting. Argus records are good for answering rate/direction/historical context questions. Ie.g. have you ever seen this host initiate a tcp connection to that host (or any host in that network), and has there ever been more data transferred out than in?</description>
		<content:encoded><![CDATA[<p>argus records are cheap to store, and they can be used for a lot of security-related things: building flow records between servers, mining flows for unusual communication patterns, mining historical traffic patterns, etc. We can cram about a year&#8217;s worth of all activity on our 20Mbps internet perimeter into about 20 gig or so worth of uncompressed argus logs. makes for some interesting hunting. Argus records are good for answering rate/direction/historical context questions. Ie.g. have you ever seen this host initiate a tcp connection to that host (or any host in that network), and has there ever been more data transferred out than in?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mumble</title>
		<link>http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-103250</link>
		<dc:creator>mumble</dc:creator>
		<pubDate>Sat, 26 Jan 2008 23:33:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/argus-auditing-network-activity-performance-status-monitoring/#comment-103250</guid>
		<description>Someone tell me what I'm missing here. As a systems administrator, I can see a lot of value in tracking the performance of Internet transactions. What I don't see are the security uses for this tool. Am I brain-damaged today?</description>
		<content:encoded><![CDATA[<p>Someone tell me what I&#8217;m missing here. As a systems administrator, I can see a lot of value in tracking the performance of Internet transactions. What I don&#8217;t see are the security uses for this tool. Am I brain-damaged today?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
