psad – Intrusion Detection with iptables, iptables Log Analysis, iptables Policy Analysis

Psad is a collection of three lightweight system daemons (two main daemons and one helper daemon) that run on Linux machines and analyze iptables log messages to detect port scans and other suspicious traffic. A typical deployment is to run psad on the iptables firewall where it has the fastest access to log data:

psad

This entry was posted in Security. Bookmark the permalink.

Leave a Reply