OpenBSD Journal

Homegrown WIDS using OpenBSD

Contributed by sean on from the scanning the ether dept.

ben writes:
As seen on NetSec, the SANS Institute has a nice article on building a wireless instrusion detection system using OpenBSD, using arpwatch, fping, xprobe, nmap, and NBTScan.
The script that is run in the deployment of WIDS has three purposes:
1) to provide a way to identify new hosts on a wireless network,
2) to collect info that is useful in identifying these hosts, and
3) to provide a method of notification to the home admin.
The article can be seen here.

(Comments are closed)


Comments
  1. By Anonymous Coward (68.116.187.71) on

    who maintains arpwatch and where can the most recent source be found?

    Comments

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]