Solved

How to check which processes keep accessing the internet?

Posted on 2000-02-13
10
258 Views
Last Modified: 2013-12-23
Anybody knows how to check if any of processes in my system(HP-UX 10.20) keeps accessing the internet?  Because recently
 I found from Cisco Router that my system has unusal traffic through
 internet,  I can just deny this system from accessing the internet but
 I want to know why and at what time which processes will access the internet.  How can I do that?
0
Comment
Question by:kslzzg
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
10 Comments
 
LVL 2

Expert Comment

by:den_tsopa
ID: 2518321
you may use lsof (list of open files)utility. it shows what processes currently have established TCP connections (and with which hosts) or listened UDP sockets.
you may get it from ftp://vic.cc.purdue.edu/pub/tools/unix/lsof/.
0
 
LVL 3

Accepted Solution

by:
klover earned 100 total points
ID: 2525961
Run a

date >> /tmp/netaccess ; netstat -a >> /tmp/netaccess

in the crontab every 10 minutes.  This appends a time stamp to the netaccess file followed by a listing of the current TCP and UDP connections on the Unix host every 10 minutes.

Read and delete the netaccess file daily.  Check the file for foreign addresses.  By analyzing the ports on the foreign and local host entries you will know what's going on.

For Example..
Proto  Local Address          Foreign Address
TCP    192.168.0.2:80  209.63.224.177:3110
TCP    192.168.0.2:1738       192.168.0.1:23

Entry one tells me that a host out on the Internet (209.63.224.177) is connected to my host at port 80.  Port 80 is the standard for WWW.

Entry two tells me that the unix host is connected to another unix host via telnet (port 23)

Using this method along with the list of known ports listed in /etc/services you can tell who connects to your server, when they are connected, and what they are doing.




0
 
LVL 3

Expert Comment

by:klover
ID: 2526056
date >> /tmp/netaccess ; netstat -a|grep localhost >> /tmp/netaccess

Use this in cron instead.  It weeds out the stuff you don't need before appending it to the netaccess file....

0
MS Dynamics Made Instantly Simpler

Make Your Microsoft Dynamics Investment Count  & Drastically Decrease Training Time by Providing Intuitive Step-By-Step WalkThru Tutorials.

 

Author Comment

by:kslzzg
ID: 2526123
I have done an experiment.  I just run ping to DNS provided by local ISP and I also run netstat but cannot find out any foreign IP address associated with the internet.  That means
I  cannot find out  the IP address for that DNS.
0
 
LVL 3

Expert Comment

by:klover
ID: 2526338
Sorry, I don't understand your experiment or what it means...
0
 

Author Comment

by:kslzzg
ID: 2529687
Let me explain what experiment I have done.   Firstly I run a process which just ping to the internet, then I run the commands that you recommend to monitor the system to see
 if I can find this process.   Definitely the "ping" process will
 trigger an ISDN connection to the internet,  why I can't find anything from "netstat -a"  regarding the internet connection?
0
 
LVL 3

Expert Comment

by:klover
ID: 2529772
Ping does not generate a session, it is just a diagnostic tool.  Your server is not sporadically pinging the Internet.  Any time your server wants to do something "real" like download mail or browse the Internet a session is created which can be detected and logged using the method described above.  For diagnostic purposes you can shorten the time to every 30 seconds, but don't let it run too long because the log will fill up your hard disk.

You know what...  I'll bet your Unix box is trying to act as a router.  If it is running RIP it will kick your router up occasionally to broadcast it's route table!!!  I had this problem at a customer site.

I'm not exactly sure how to tell you to disable RIP on HP-UX.  Poke around in your network configuration...  Maybe see if it is running as a process...

ps -ef|grep rip

More later if I find anything...
0
 
LVL 3

Expert Comment

by:klover
ID: 2529793
Just remembered, I had to shutdown the route daemon.  

ps -ef|grep routed

This will tell you if the route daemon is running on your system.
0
 
LVL 3

Expert Comment

by:klover
ID: 2529828
(gated also uses RIP)  ps -ef|grep gated

The well known port for the Routed daemon to wait for routing information packets is UDP socket 520.

do a

netstat -a -n | grep 520

to see if you are running a RIP router on your Unix box.  If you are, RIP is most likely generating that traffic.
0
 

Author Comment

by:kslzzg
ID: 2530035
No, I still got nothing from "ps -ef|grep gated" and  
   "netstat -a -n | grep 520".  I believe it has something to do
 with a  performance monitoring demo software from teamquest.com   which I have just installed last Friday.
 Before last Friday, there is no such traffic.   But I still don't know why and how,   I am still investigating it.  

More later if I find anything...
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question