Argus

From Forensics Wiki
Revision as of 11:54, 31 August 2009 by Carter (Talk | contribs)

Jump to: navigation, search

Overview

argus is a network flow monitor that is used to establish network activity audits, that are then used to supplement traditional IDS based network security. These sites use contemporary IDS technology like snort and/or Bro to generate events and alarms, and then use the Argus network audit data to provide context for those alarms to decide if the alarms are real problems. In many DIY efforts, snort, Bro and argus run on the same high performance device. The audit data that Argus generates is great for network forensics, non-repudiation, network asset and service inventory, behavioral baselining of server and client relationships, detecting very slow scans, and supporting Zero day events. The network transaction audit data that Argus generates has also been used for a wide range of other tasks including Network Billing and Accounting, Operations Management and Performance Analysis.

Argus uses libpcap and it has been ported to virtually every Unix platform, OpenWRT and on Win32 using Cygwin.

See Also