ISA automatically contact whois email of an attacker?

Alright,
I frequently am getting alerts from ISA server informing me of a "port scan" or other attack. Does anyone know of a way that I can get ISA to automatically take the offending IP, whois it, get the contact email, and email them telling them the IP of the attacker?

Let me know of any ideas. Thanks,
Matt
LVL 2
hattmardyAsked:
Who is Participating?
 
Tim HolmanConnect With a Mentor Commented:
If you can get the log-file into a text readable format, you could knock up a batch script to do this for you.
However...  if I were you, I would ignore these port-scans and put them down to white noise.
Everytime you report someone, there'll be another 10 on your doorstep.
Also, automated emails are spam, so make sure you don't get into trouble !
0
 
chris_calabreseConnect With a Mentor Commented:
This is usually not considered worthwhile since a) its very hard to get an ISP to act just based on port scanning, b) most of this type of traffic is generated from worms and such, so there's no hope of keeping up with the deluge of differnt addresses, following up on each one, etc., and c) "real" attackers (the kind you need to worry about) are likely to notice that you did the whois lookup and sent the email so they'll know that you're watching.
0
 
hattmardyAuthor Commented:
Thanks guys, you both made good points. I split the points. Keep up the good work.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.