Solved

How to check which processes keep accessing the internet?

Posted on 2000-02-13
10
247 Views
Last Modified: 2013-12-23
Anybody knows how to check if any of processes in my system(HP-UX 10.20) keeps accessing the internet?  Because recently
 I found from Cisco Router that my system has unusal traffic through
 internet,  I can just deny this system from accessing the internet but
 I want to know why and at what time which processes will access the internet.  How can I do that?
0
Comment
Question by:kslzzg
  • 6
  • 3
10 Comments
 
LVL 2

Expert Comment

by:den_tsopa
ID: 2518321
you may use lsof (list of open files)utility. it shows what processes currently have established TCP connections (and with which hosts) or listened UDP sockets.
you may get it from ftp://vic.cc.purdue.edu/pub/tools/unix/lsof/.
0
 
LVL 3

Accepted Solution

by:
klover earned 100 total points
ID: 2525961
Run a

date >> /tmp/netaccess ; netstat -a >> /tmp/netaccess

in the crontab every 10 minutes.  This appends a time stamp to the netaccess file followed by a listing of the current TCP and UDP connections on the Unix host every 10 minutes.

Read and delete the netaccess file daily.  Check the file for foreign addresses.  By analyzing the ports on the foreign and local host entries you will know what's going on.

For Example..
Proto  Local Address          Foreign Address
TCP    192.168.0.2:80  209.63.224.177:3110
TCP    192.168.0.2:1738       192.168.0.1:23

Entry one tells me that a host out on the Internet (209.63.224.177) is connected to my host at port 80.  Port 80 is the standard for WWW.

Entry two tells me that the unix host is connected to another unix host via telnet (port 23)

Using this method along with the list of known ports listed in /etc/services you can tell who connects to your server, when they are connected, and what they are doing.




0
 
LVL 3

Expert Comment

by:klover
ID: 2526056
date >> /tmp/netaccess ; netstat -a|grep localhost >> /tmp/netaccess

Use this in cron instead.  It weeds out the stuff you don't need before appending it to the netaccess file....

0
 

Author Comment

by:kslzzg
ID: 2526123
I have done an experiment.  I just run ping to DNS provided by local ISP and I also run netstat but cannot find out any foreign IP address associated with the internet.  That means
I  cannot find out  the IP address for that DNS.
0
 
LVL 3

Expert Comment

by:klover
ID: 2526338
Sorry, I don't understand your experiment or what it means...
0
Give your grad a cloud of their own!

With up to 8TB of storage, give your favorite graduate their own personal cloud to centralize all their photos, videos and music in one safe place. They can save, sync and share all their stuff, and automatic photo backup helps free up space on their smartphone and tablet.

 

Author Comment

by:kslzzg
ID: 2529687
Let me explain what experiment I have done.   Firstly I run a process which just ping to the internet, then I run the commands that you recommend to monitor the system to see
 if I can find this process.   Definitely the "ping" process will
 trigger an ISDN connection to the internet,  why I can't find anything from "netstat -a"  regarding the internet connection?
0
 
LVL 3

Expert Comment

by:klover
ID: 2529772
Ping does not generate a session, it is just a diagnostic tool.  Your server is not sporadically pinging the Internet.  Any time your server wants to do something "real" like download mail or browse the Internet a session is created which can be detected and logged using the method described above.  For diagnostic purposes you can shorten the time to every 30 seconds, but don't let it run too long because the log will fill up your hard disk.

You know what...  I'll bet your Unix box is trying to act as a router.  If it is running RIP it will kick your router up occasionally to broadcast it's route table!!!  I had this problem at a customer site.

I'm not exactly sure how to tell you to disable RIP on HP-UX.  Poke around in your network configuration...  Maybe see if it is running as a process...

ps -ef|grep rip

More later if I find anything...
0
 
LVL 3

Expert Comment

by:klover
ID: 2529793
Just remembered, I had to shutdown the route daemon.  

ps -ef|grep routed

This will tell you if the route daemon is running on your system.
0
 
LVL 3

Expert Comment

by:klover
ID: 2529828
(gated also uses RIP)  ps -ef|grep gated

The well known port for the Routed daemon to wait for routing information packets is UDP socket 520.

do a

netstat -a -n | grep 520

to see if you are running a RIP router on your Unix box.  If you are, RIP is most likely generating that traffic.
0
 

Author Comment

by:kslzzg
ID: 2530035
No, I still got nothing from "ps -ef|grep gated" and  
   "netstat -a -n | grep 520".  I believe it has something to do
 with a  performance monitoring demo software from teamquest.com   which I have just installed last Friday.
 Before last Friday, there is no such traffic.   But I still don't know why and how,   I am still investigating it.  

More later if I find anything...
0

Featured Post

Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

Join & Write a Comment

Suggested Solutions

I was recently sitting at a desk at work with one of my colleagues and needed some information on my home computer. He watched as I turned on my home computer, established a remote session into it, got the information I needed and then shut it down …
What is IRC? IRC (Internet Relay Chat) is a form of communication between multiple users. It is available freely to anyone with inernet access. IRC is a great way to communicate with others e.g. There is an IRC channel for Ubuntu Linux, which is fo…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now