IDS Statistics generated on Tue Sep 14 04:41:54 2010 SnortALog

The log begins at :Jan 01 00:17:46
The log ends at :Dec 31 23:55:45
Total of Lines in log file :99420
Total of Logs Dropped :198 (0.20%)
Total events in table :16922
Source IP recorded :935
Destination IP recorded :5
Host logger recorded :1 with 1 interface(s)
Signatures recorded :41
Classification recorded :12
Severity recorded :4
Portscan detected :0
Domains File : conf/domains
Number of domains : 267
Rules File : conf/rules
Number of referenced rules : 2226

Legend :
RED :Dangerous connection (potentially bad, further investigation needed)
GREEN :Warning connection (strange, may need further intevestigation)
BLACK :Not dangerous alert

Popularity of one source host

%NoIP SourceResolveDomain
4.66788 66.154.102.38 unresolved Unresolved
4.15703 192.168.24.52 unresolved Unresolved
4.12698 130.54.208.193 natto.kuee.kyoto-u.ac.jp Japan
3.24548 74.6.74.226 UNKNOWN-74-6-74-226.yahoo.com .COM
2.17367 68.142.250.92 UNKNOWN-68-142-250-92.yahoo.com .COM
2.13360 74.6.85.164 UNKNOWN-74-6-85-164.yahoo.com .COM
1.86315 72.30.103.92 kp227030.inktomisearch.com .COM
1.63275 74.6.74.213 UNKNOWN-74-6-74-213.yahoo.com .COM
1.61272 207.46.98.48 msnbot.msn.com .COM
1.54261 207.46.98.49 msnbot.msn.com .COM
1.53259 72.30.252.148 UNKNOWN-72-30-252-148.yahoo.com .COM
1.39235 207.46.98.47 msnbot.msn.com .COM
1.27215 74.6.74.187 UNKNOWN-74-6-74-187.yahoo.com .COM
1.24209 72.30.110.224 b5121162.yst.yahoo.net .NET
1.19202 72.30.226.199 ha7.ge-13-35.bas-1-con.ac2.yahoo.com .COM
1.08183 74.6.75.34 UNKNOWN-74-6-75-34.yahoo.com .COM
1.00170 74.6.65.238 UNKNOWN-74-6-65-238.yahoo.com .COM
0.99168 72.30.97.215 UNKNOWN-72-30-97-215.yahoo.com .COM
0.95160 72.30.102.22 UNKNOWN-72-30-102-22.yahoo.com .COM
0.91154 72.30.111.201 ge-1-0.bas1-1-con.ac2.yahoo.com .COM
0.89150 68.142.250.76 admin1.ops.dxs.yahoo.com .COM
0.87148 74.6.74.214 UNKNOWN-74-6-74-214.yahoo.com .COM
0.87147 74.6.74.170 UNKNOWN-74-6-74-170.yahoo.com .COM
0.85144 207.46.98.52 msnbot.msn.com .COM
0.85143 74.6.75.21 UNKNOWN-74-6-75-21.yahoo.com .COM
0.85143 65.214.44.135 unresolved Unresolved
0.82139 68.142.250.35 vl107.bas2-1-str.dxs.yahoo.com .COM
0.80136 72.30.252.85 UNKNOWN-72-30-252-85.yahoo.com .COM
0.80135 72.30.98.147 UNKNOWN-72-30-98-147.yahoo.com .COM
0.74125 72.30.98.27 mwp515001.inktomisearch.com .COM

Popularity of one destination host

%NoIP DestinationResolve
99.8216891 192.168.24.11 natsume.tuchiya.org
0.1221 192.168.24.1 unresolved
0.024 192.168.24.10 hoozuki.tuchiya.org
0.023 210.236.178.117dhcp178-116.ztv.ne.jp
0.011 131.112.174.57 gogh.pi.titech.ac.jp

Attacks from one host to any with same method

%NoIP SourceAttackSeverity
4.66788 66.154.102.38 WEB-MISC robots.txt access {tcp} medium
3.24548 74.6.74.226 WEB-MISC robots.txt access {tcp} medium
2.53428 130.54.208.193 IMAP fetch overflow attempt {tcp} medium
2.17367 68.142.250.92 WEB-MISC robots.txt access {tcp} medium
2.13360 74.6.85.164 WEB-MISC robots.txt access {tcp} medium
1.94328 192.168.24.52 (http_inspect) IIS UNICODE CODEPOINT ENCODING {tcp} unknown
1.93326 192.168.24.52 (http_inspect) BARE BYTE UNICODE ENCODING {tcp} unknown
1.86315 72.30.103.92 WEB-MISC robots.txt access {tcp} medium
1.63275 74.6.74.213 WEB-MISC robots.txt access {tcp} medium
1.61272 207.46.98.48 WEB-MISC robots.txt access {tcp} medium
1.54261 207.46.98.49 WEB-MISC robots.txt access {tcp} medium
1.53259 72.30.252.148 WEB-MISC robots.txt access {tcp} medium
1.39235 207.46.98.47 WEB-MISC robots.txt access {tcp} medium
1.32223 130.54.208.193 IMAP status overflow attempt {tcp} medium
1.27215 74.6.74.187 WEB-MISC robots.txt access {tcp} medium
1.24209 72.30.110.224 WEB-MISC robots.txt access {tcp} medium
1.19202 72.30.226.199 WEB-MISC robots.txt access {tcp} medium
1.08183 74.6.75.34 WEB-MISC robots.txt access {tcp} medium
1.00170 74.6.65.238 WEB-MISC robots.txt access {tcp} medium
0.99168 72.30.97.215 WEB-MISC robots.txt access {tcp} medium
0.95160 72.30.102.22 WEB-MISC robots.txt access {tcp} medium
0.91154 72.30.111.201 WEB-MISC robots.txt access {tcp} medium
0.89150 68.142.250.76 WEB-MISC robots.txt access {tcp} medium
0.87148 74.6.74.214 WEB-MISC robots.txt access {tcp} medium
0.87147 74.6.74.170 WEB-MISC robots.txt access {tcp} medium
0.85144 207.46.98.52 WEB-MISC robots.txt access {tcp} medium
0.85143 65.214.44.135 WEB-MISC robots.txt access {tcp} medium
0.85143 74.6.75.21 WEB-MISC robots.txt access {tcp} medium
0.82139 68.142.250.35 WEB-MISC robots.txt access {tcp} medium
0.80136 72.30.252.85 WEB-MISC robots.txt access {tcp} medium

Attacks to one host from any with same method

%NoIP DestinationAttackSeverity
87.2814770 192.168.24.11 WEB-MISC robots.txt access {tcp} medium
2.78470 192.168.24.11 IMAP fetch overflow attempt {tcp} medium
2.54430 192.168.24.11 (http_inspect) BARE BYTE UNICODE ENCODING {tcp} unknown
2.05347 192.168.24.11 (http_inspect) IIS UNICODE CODEPOINT ENCODING {tcp} unknown
1.51256 192.168.24.11 IMAP status overflow attempt {tcp} medium
0.85144 192.168.24.11 WEB-MISC Invalid HTTP Version String {tcp} medium
0.5085 192.168.24.11 WEB-IIS view source via translate header {tcp} medium
0.5084 192.168.24.11 ICMP Destination Unreachable Communication Administratively Prohibited {icmp}low
0.3254 192.168.24.11 (http_inspect) OVERSIZE CHUNK ENCODING {tcp} unknown
0.2949 192.168.24.11 (http_inspect) OVERSIZE REQUEST-URI DIRECTORY {tcp} unknown
0.2542 192.168.24.11 ICMP Destination Unreachable Communication Administratively Prohibited {udp}low
0.2238 192.168.24.11 WEB-MISC http directory traversal {tcp} medium
0.1017 192.168.24.11 NETBIOS SMB trans2open buffer overflow attempt {tcp} high
0.0916 192.168.24.1 (portscan) ICMP Sweep {proto255} unknown
0.0813 192.168.24.11 WEB-PHP test.php access {tcp} medium
0.0813 192.168.24.11 (snort_decoder) WARNING: TCP Data Offset is less than 5! {tcp} unknown
0.059 192.168.24.11 WEB-MISC apache directory disclosure attempt {tcp} medium
0.059 192.168.24.11 WEB-MISC Chunked-Encoding transfer attempt {tcp} high
0.046 192.168.24.11 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited {icmp}low
0.046 192.168.24.11 WEB-FRONTPAGE /_vti_bin/ access {tcp} medium
0.035 192.168.24.1 (portscan) ICMP Sweep {proto255} medium
0.035 192.168.24.11 IMAP authenticate overflow attempt {tcp} medium
0.024 192.168.24.11 WEB-PHP remote include path {tcp} high
0.024 192.168.24.11 MS-SQL probe response overflow attempt {udp} high
0.024 192.168.24.11 ATTACK-RESPONSES id check returned root {udp} medium
0.024 192.168.24.11 (http_inspect) DOUBLE DECODING ATTACK {tcp} unknown
0.024 192.168.24.10 ATTACK-RESPONSES id check returned root {udp} medium
0.024 192.168.24.11 WEB-MISC cross site scripting attempt {tcp} high
0.024 192.168.24.11 SNMP request udp {udp} medium
0.023 192.168.24.11 (http_inspect) OVERSIZE CHUNK ENCODING {tcp} medium

Attacks from a host to a destination

%NoIP SourceIP DestinationAttack
4.66788 66.154.102.38 192.168.24.11 WEB-MISC robots.txt access {tcp}
3.24548 74.6.74.226 192.168.24.11 WEB-MISC robots.txt access {tcp}
2.53428 130.54.208.193 192.168.24.11 IMAP fetch overflow attempt {tcp}
2.17367 68.142.250.92 192.168.24.11 WEB-MISC robots.txt access {tcp}
2.13360 74.6.85.164 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.94328 192.168.24.52 192.168.24.11 (http_inspect) IIS UNICODE CODEPOINT ENCODING {tcp}
1.93326 192.168.24.52 192.168.24.11 (http_inspect) BARE BYTE UNICODE ENCODING {tcp}
1.86315 72.30.103.92 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.63275 74.6.74.213 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.61272 207.46.98.48 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.54261 207.46.98.49 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.53259 72.30.252.148 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.39235 207.46.98.47 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.32223 130.54.208.193 192.168.24.11 IMAP status overflow attempt {tcp}
1.27215 74.6.74.187 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.24209 72.30.110.224 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.19202 72.30.226.199 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.08183 74.6.75.34 192.168.24.11 WEB-MISC robots.txt access {tcp}
1.00170 74.6.65.238 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.99168 72.30.97.215 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.95160 72.30.102.22 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.91154 72.30.111.201 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.89150 68.142.250.76 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.87148 74.6.74.214 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.87147 74.6.74.170 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.85144 207.46.98.52 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.85143 74.6.75.21 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.85143 65.214.44.135 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.82139 68.142.250.35 192.168.24.11 WEB-MISC robots.txt access {tcp}
0.80136 72.30.252.85 192.168.24.11 WEB-MISC robots.txt access {tcp}

Distribution of attack methods

%NoAttackPrioritySeverity
87.2814770 WEB-MISC robots.txt access {tcp} 2medium
2.78470 IMAP fetch overflow attempt {tcp} 2medium
2.54430 (http_inspect) BARE BYTE UNICODE ENCODING {tcp} 2unknown
2.05347 (http_inspect) IIS UNICODE CODEPOINT ENCODING {tcp} 2unknown
1.51256 IMAP status overflow attempt {tcp} 2medium
0.85144 WEB-MISC Invalid HTTP Version String {tcp} 2medium
0.5085 WEB-IIS view source via translate header {tcp} 2medium
0.5084 ICMP Destination Unreachable Communication Administratively Prohibited {icmp}3low
0.3153 (http_inspect) OVERSIZE CHUNK ENCODING {tcp} 2unknown
0.2949 (http_inspect) OVERSIZE REQUEST-URI DIRECTORY {tcp} 2unknown
0.2542 ICMP Destination Unreachable Communication Administratively Prohibited {udp}3low
0.2238 WEB-MISC http directory traversal {tcp} 2medium
0.1017 NETBIOS SMB trans2open buffer overflow attempt {tcp} 1high
0.0916 (portscan) ICMP Sweep {proto255} 2unknown
0.0813 (snort_decoder) WARNING: TCP Data Offset is less than 5! {tcp} 2unknown
0.0813 WEB-PHP test.php access {tcp} 2medium
0.059 WEB-MISC Chunked-Encoding transfer attempt {tcp} 1high
0.059 WEB-MISC apache directory disclosure attempt {tcp} 2medium
0.058 ATTACK-RESPONSES id check returned root {udp} 2medium
0.046 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited {icmp}3low
0.046 (portscan) ICMP Sweep {proto255} 2medium
0.046 WEB-FRONTPAGE /_vti_bin/ access {tcp} 2medium
0.035 IMAP authenticate overflow attempt {tcp} 2medium
0.024 MS-SQL probe response overflow attempt {udp} 1high
0.024 (http_inspect) DOUBLE DECODING ATTACK {tcp} 2unknown
0.024 WEB-MISC cross site scripting attempt {tcp} 1high
0.024 SNMP request udp {udp} 2medium
0.024 WEB-PHP remote include path {tcp} 1high
0.023 ATTACK-RESPONSES 403 Forbidden {tcp} 2medium
0.023 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited {tcp}3low
0.023 (http_inspect) OVERSIZE CHUNK ENCODING {tcp} 2medium
0.023 WEB-MISC /etc/passwd {tcp} 2medium
0.012 SNMP private access udp {udp} 2medium
0.012 WEB-MISC WebDAV search access {tcp} 2medium
0.012 SNMP public access udp {udp} 2medium
0.011 WEB-MISC Cisco IOS HTTP configuration attempt {tcp} 1high
0.011 WEB-MISC long basic authorization string {tcp} 2medium
0.011 (http_inspect) BARE BYTE UNICODE ENCODING {tcp} 2medium
0.011 (http_inspect) OVERSIZE REQUEST-URI DIRECTORY {tcp} 2medium
0.011 (http_inspect) OVERSIZE CHUNK ENCODING {tcp} 3unknown
0.011 (http_inspect) BARE BYTE UNICODE ENCODING {tcp} 1high

Distribution of classification method

%NoClassificationSeverity
87.9614884 access to a potentially vulnerable web application medium
5.32900 http_inspect unknown
4.32731 Misc Attack medium
0.86146 Detection of a non-standard protocol or event medium
0.80135 Misc activity low
0.3153 Attempted Information Leak medium
0.1119 Web Application Attack high
0.1017 Attempted Administrator Privilege Gain high
0.0813 snort_decoder unknown
0.0610 Attempted Denial of Service medium
0.058 Potentially Bad Traffic medium
0.024 Attempted User Privilege Gain high

Distribution of event by severity

%NoSeverity
93.5615832 medium
5.40913 unknown
0.80135 low
0.2440 high

Distribution of event by day


DayMonthNo%Graph
1 03 46 0.27
1 07 60 0.35
1 12 46 0.27
1 10 48 0.28
1 08 23 0.14
1 11 42 0.25
1 01 54 0.32
1 05 93 0.55
1 09 27 0.16
1 02 65 0.38
1 06 58 0.34
2 01 46 0.27
2 07 50 0.30
2 03 53 0.31
2 09 43 0.25
2 05 99 0.59
2 02 48 0.28
2 06 70 0.41
2 12 45 0.27
2 08 36 0.21
2 11 38 0.22
2 10 52 0.31
3 01 57 0.34
3 05 126 0.74
3 12 39 0.23
3 09 36 0.21
3 08 24 0.14
3 07 55 0.33
3 03 43 0.25
3 10 58 0.34
3 06 69 0.41
3 11 35 0.21
3 02 66 0.39
4 10 66 0.39
4 08 22 0.13
4 03 33 0.20
4 12 39 0.23
4 05 92 0.54
4 09 46 0.27
4 02 65 0.38
4 06 56 0.33
4 01 40 0.24
4 07 47 0.28
4 11 30 0.18
5 02 58 0.34
5 10 50 0.30
5 05 101 0.60
5 01 61 0.36
5 06 62 0.37
5 07 55 0.33
5 11 45 0.27
5 08 37 0.22
5 03 43 0.25
5 09 42 0.25
5 12 41 0.24
6 07 51 0.30
6 08 43 0.25
6 12 31 0.18
6 09 36 0.21
6 11 39 0.23
6 05 99 0.59
6 02 88 0.52
6 06 83 0.49
6 10 48 0.28
6 01 27 0.16
7 07 36 0.21
7 01 67 0.40
7 06 63 0.37
7 09 35 0.21
7 11 32 0.19
7 12 25 0.15
7 10 41 0.24
7 08 54 0.32
7 05 95 0.56
7 02 95 0.56
8 11 33 0.20
8 09 37 0.22
8 10 32 0.19
8 02 62 0.37
8 08 59 0.35
8 12 41 0.24
8 07 50 0.30
8 06 76 0.45
8 05 74 0.44
8 01 41 0.24
9 07 40 0.24
9 02 63 0.37
9 08 32 0.19
9 10 29 0.17
9 09 44 0.26
9 05 84 0.50
9 01 72 0.43
9 12 35 0.21
9 06 52 0.31
9 11 31 0.18
1009 44 0.26
1005 82 0.48
1002 36 0.21
1012 55 0.33
1006 45 0.27
1011 31 0.18
1007 44 0.26
1010 23 0.14
1008 48 0.28
1001 42 0.25
1105 60 0.35
1101 46 0.27
1109 39 0.23
1107 46 0.27
1106 61 0.36
1102 60 0.35
1111 45 0.27
1110 28 0.17
1108 27 0.16
1112 42 0.25
1205 97 0.57
1210 23 0.14
1206 59 0.35
1207 49 0.29
1201 46 0.27
1211 42 0.25
1202 70 0.41
1208 24 0.14
1209 25 0.15
1212 51 0.30
1306 49 0.29
1305 82 0.48
1311 41 0.24
1302 56 0.33
1310 28 0.17
1309 35 0.21
1301 55 0.33
1308 17 0.10
1312 64 0.38
1307 41 0.24
1408 25 0.15
1410 33 0.20
1405 112 0.66
1402 83 0.49
1407 48 0.28
1409 30 0.18
1411 47 0.28
1412 64 0.38
1406 53 0.31
1401 28 0.17
1507 42 0.25
1505 120 0.71
1506 69 0.41
1512 45 0.27
1508 35 0.21
1502 46 0.27
1510 39 0.23
1501 49 0.29
1511 43 0.25
1509 29 0.17
1610 33 0.20
1607 41 0.24
1602 54 0.32
1612 53 0.31
1601 65 0.38
1611 35 0.21
1606 78 0.46
1609 23 0.14
1605 93 0.55
1608 40 0.24
1709 29 0.17
1704 17 0.10
1706 48 0.28
1707 36 0.21
1711 37 0.22
1705 146 0.86
1702 65 0.38
1710 37 0.22
1708 28 0.17
1712 44 0.26
1701 49 0.29
1801 39 0.23
1809 51 0.30
1805 162 0.96
1806 42 0.25
1802 52 0.31
1810 51 0.30
1807 48 0.28
1811 61 0.36
1804 44 0.26
1808 22 0.13
1812 72 0.43
1904 48 0.28
1912 73 0.43
1901 47 0.28
1905 93 0.55
1907 40 0.24
1902 51 0.30
1911 39 0.23
1910 37 0.22
1906 55 0.33
1908 23 0.14
1909 51 0.30
2001 24 0.14
2005 93 0.55
2009 29 0.17
2002 45 0.27
2010 27 0.16
2004 54 0.32
2006 65 0.38
2007 38 0.22
2011 38 0.22
2008 33 0.20
2012 71 0.42
2101 32 0.19
2104 59 0.35
2111 40 0.24
2105 152 0.90
2106 59 0.35
2112 82 0.48
2102 49 0.29
2107 53 0.31
2108 24 0.14
2110 26 0.15
2109 24 0.14
2206 64 0.38
2209 30 0.18
2212 70 0.41
2210 39 0.23
2207 37 0.22
2201 15 0.09
2208 25 0.15
2205 174 1.03
2204 61 0.36
2202 60 0.35
2211 33 0.20
2310 35 0.21
2304 57 0.34
2302 22 0.13
2308 31 0.18
2307 39 0.23
2301 18 0.11
2306 76 0.45
2312 60 0.35
2305 138 0.82
2309 31 0.18
2311 30 0.18
2408 21 0.12
2411 41 0.24
2407 30 0.18
2402 45 0.27
2412 47 0.28
2406 63 0.37
2405 122 0.72
2401 49 0.29
2404 68 0.40
2409 32 0.19
2410 41 0.24
2510 29 0.17
2509 35 0.21
2502 34 0.20
2508 37 0.22
2512 59 0.35
2501 60 0.35
2507 37 0.22
2506 50 0.30
2505 302 1.78
2511 34 0.20
2504 80 0.47
2612 52 0.31
2605 287 1.70
2607 31 0.18
2602 47 0.28
2601 67 0.40
2609 39 0.23
2606 62 0.37
2608 31 0.18
2611 37 0.22
2604 101 0.60
2610 29 0.17
2704 90 0.53
2712 53 0.31
2702 52 0.31
2706 56 0.33
2705 153 0.90
2710 31 0.18
2709 27 0.16
2708 20 0.12
2701 88 0.52
2707 39 0.23
2711 41 0.24
2806 54 0.32
2811 30 0.18
2812 66 0.39
2807 37 0.22
2802 59 0.35
2808 31 0.18
2804 69 0.41
2801 77 0.46
2805 120 0.71
2809 38 0.22
2810 32 0.19
2905 56 0.33
2912 45 0.27
2908 33 0.20
2906 45 0.27
2910 56 0.33
2904 57 0.34
2907 38 0.22
2911 32 0.19
2909 53 0.31
2901 59 0.35
3012 32 0.19
3006 55 0.33
3009 35 0.21
3007 44 0.26
3004 80 0.47
3011 35 0.21
3010 35 0.21
3001 57 0.34
3008 29 0.17
3005 67 0.40
3110 27 0.16
3105 38 0.22
3107 29 0.17
3108 35 0.21
3101 59 0.35
3112 59 0.35


Distribution of attack by hour

HourNo%Graph
0h695 4.11
1h656 3.88
2h644 3.81
3h654 3.86
4h654 3.86
5h637 3.76
6h696 4.11
7h714 4.22
8h784 4.63
9h731 4.32
10h720 4.25
11h674 3.98
12h721 4.26
13h695 4.11
14h677 4.00
15h667 3.94
16h649 3.84
17h673 3.98
18h645 3.81
19h665 3.93
20h682 4.03
21h737 4.36
22h925 5.47
23h925 5.47



Attacks by hour

%NoHourAttack
3.97672 10hWEB-MISC robots.txt access {tcp}
3.92663 7hWEB-MISC robots.txt access {tcp}
3.81645 3hWEB-MISC robots.txt access {tcp}
3.79641 6hWEB-MISC robots.txt access {tcp}
3.78639 22hWEB-MISC robots.txt access {tcp}
3.74633 12hWEB-MISC robots.txt access {tcp}
3.71627 2hWEB-MISC robots.txt access {tcp}
3.69625 13hWEB-MISC robots.txt access {tcp}
3.69624 19hWEB-MISC robots.txt access {tcp}
3.68623 4hWEB-MISC robots.txt access {tcp}
3.65618 20hWEB-MISC robots.txt access {tcp}
3.65617 5hWEB-MISC robots.txt access {tcp}
3.62613 23hWEB-MISC robots.txt access {tcp}
3.59608 8hWEB-MISC robots.txt access {tcp}
3.59607 11hWEB-MISC robots.txt access {tcp}
3.58606 21hWEB-MISC robots.txt access {tcp}
3.58605 15hWEB-MISC robots.txt access {tcp}
3.53598 1hWEB-MISC robots.txt access {tcp}
3.50593 17hWEB-MISC robots.txt access {tcp}
3.49591 18hWEB-MISC robots.txt access {tcp}
3.46586 0hWEB-MISC robots.txt access {tcp}
3.44582 14hWEB-MISC robots.txt access {tcp}
3.42578 16hWEB-MISC robots.txt access {tcp}
3.40576 9hWEB-MISC robots.txt access {tcp}
0.94159 23h(http_inspect) IIS UNICODE CODEPOINT ENCODING {tcp}
0.81137 8hIMAP fetch overflow attempt {tcp}
0.77130 22h(http_inspect) BARE BYTE UNICODE ENCODING {tcp}
0.72122 22h(http_inspect) IIS UNICODE CODEPOINT ENCODING {tcp}
0.66111 23h(http_inspect) BARE BYTE UNICODE ENCODING {tcp}
0.61103 9hIMAP fetch overflow attempt {tcp}

Distribution of event by destination port

%NoDestination Port
95.1416099 80
4.32731 143
0.2542 3/13
0.1017 139
0.0813 0
0.058 161
0.023 3/10
0.012 32768
0.012 1025
0.011 51922
0.011 51885
0.011 51944

Attacks to one destination port

%NoPortAttack
87.2814770 80 WEB-MISC robots.txt access {tcp}
2.78470 143 IMAP fetch overflow attempt {tcp}
2.55432 80 (http_inspect) BARE BYTE UNICODE ENCODING {tcp}
2.05347 80 (http_inspect) IIS UNICODE CODEPOINT ENCODING {tcp}
1.51256 143 IMAP status overflow attempt {tcp}
0.85144 80 WEB-MISC Invalid HTTP Version String {tcp}
0.5085 80 WEB-IIS view source via translate header {tcp}
0.3457 80 (http_inspect) OVERSIZE CHUNK ENCODING {tcp}
0.3050 80 (http_inspect) OVERSIZE REQUEST-URI DIRECTORY {tcp}
0.2542 80 ICMP Destination Unreachable Communication Administratively Prohibited {udp}
0.2542 3/13 ICMP Destination Unreachable Communication Administratively Prohibited {icmp}
0.2542 80 ICMP Destination Unreachable Communication Administratively Prohibited {icmp}
0.2238 80 WEB-MISC http directory traversal {tcp}
0.1322 80 (portscan) ICMP Sweep {proto255}
0.1017 139 NETBIOS SMB trans2open buffer overflow attempt {tcp}
0.0813 0 (snort_decoder) WARNING: TCP Data Offset is less than 5! {tcp}
0.0813 80 WEB-PHP test.php access {tcp}
0.059 80 WEB-MISC apache directory disclosure attempt {tcp}
0.059 80 WEB-MISC Chunked-Encoding transfer attempt {tcp}
0.058 80 ATTACK-RESPONSES id check returned root {udp}
0.046 80 WEB-FRONTPAGE /_vti_bin/ access {tcp}
0.035 143 IMAP authenticate overflow attempt {tcp}
0.024 80 WEB-PHP remote include path {tcp}
0.024 80 (http_inspect) DOUBLE DECODING ATTACK {tcp}
0.024 161 SNMP request udp {udp}
0.024 80 WEB-MISC cross site scripting attempt {tcp}
0.023 3/10 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited {icmp}
0.023 80 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited {icmp}
0.023 80 WEB-MISC /etc/passwd {tcp}
0.023 80 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited {tcp}

Popularity of one domain

%NoDomain
46.63436 .COM
20.96196 Unresolved
14.33134 Japan
10.1695 .NET
1.7116 Seychelles
1.1811 Poland
0.535 Brazil
0.323 France
0.323 Thailand
0.323 US Educational
0.323 Italy
0.212 Russian Federation
0.212 .ORG
0.212 Germany
0.212
0.212 Switzerland
0.212 Pakistan
0.212 Argentina
0.111 Portugal
0.111 China
0.111 Spain
0.111 Malaysia
0.111 Romania
0.111 India
0.111 Singapore
0.111 Czech Republic
0.111 US Military
0.111 Chile
0.111 Dominican Republic
0.111 Greece

Distribution of event by protocols

%NoProtocols
98.9616746 tcp
0.5390 icmp
0.3762 udp
0.1322 proto255



Main Stats
IP Src
IP Dst
Protocols
Hour
Days
Services
Source Log

IDS/IPS Stats
Attack by Src
Attack by Dst
Attack by Src and Dst
Attacks
Alert Severity
Alert Classification
Attacks by Services
Attacks by Hours

 
 
   
 
 
powered by SnortALog
© SnortALog 2000-2005