psad: Port Scan Attack Detector

psad is a collection of three lightweight system daemons (two main daemons and one helper daemon) that run on Linux machines and analyze iptables log messages to detect port scans and other suspicious traffic.

psad: Port Scan Attack Detector screenshot 1

Cost / License

  • Free
  • Open Source

Application type

Platforms

  • Linux
-
No reviews
0likes
0comments
0news articles

Features

Suggest and vote on features
  1.  Command line interface
  2.  Ad-free
  3.  Honeypot
  4.  Network intrusion detection system

 Tags

psad: Port Scan Attack Detector News & Activities

Highlights All activities

Recent activities

No activities found.

psad: Port Scan Attack Detector information

  • Developed by

    Michael Rash
  • Licensing

    Open Source (GPL-2.0) and Free product.
  • Written in

  • Alternatives

    3 alternatives listed
  • Supported Languages

    • English

AlternativeTo Categories

Security & PrivacyNetwork & AdminOS & Utilities

GitHub repository

  •  416 Stars
  •  76 Forks
  •  29 Open Issues
  •   Updated  
View on GitHub

Popular alternatives

    View all
    psad: Port Scan Attack Detector was added to AlternativeTo by RemovedUser on and this page was last updated .
    No comments or reviews, maybe you want to be first?
    Post comment/review

    What is psad: Port Scan Attack Detector?

    psad is a collection of three lightweight system daemons (two main daemons and one helper daemon) that run on Linux machines and analyze iptables log messages to detect port scans and other suspicious traffic. A typical deployment is to run psad on the iptables firewall where it has the fastest access to log data.

    psad incorporates many signatures from the Snort intrusion detection system to detect probes for various backdoor programs (e.g. EvilFTP, GirlFriend, SubSeven), DDoS tools (mstream, shaft), and advanced port scans (FIN, NULL, XMAS) which are easily leveraged against a machine via nmap. When combined with fwsnort and the Netfilter string match extension, psad is capable of detecting many attacks described in the Snort rule set that involve application layer data. In addition, psad makes use of various packet header fields associated with TCP SYN packets to passively fingerprint remote operating systems (in a manner similar to p0f) from which scans originate. Further, psad can be integrated with Logstash, and also offers support for UFW firewalls.

    Official Links