Solved

How to detect and kill unauthorized network activity

Posted on 2011-03-10
7
950 Views
Last Modified: 2014-09-22
I am a school network admin.  How can I detect when my students are using tools like PUTTY and Ultrasurf to bypass webfiltering and how can I detect and track DOS attacks from the student workstations?  We do not allow non-distrooct devices to attach to the network.  M7y best solution would be to detect and identify the activity, e-mail me about it, and allow me to either control it, or track it to a port on a switch. Additionally, if I could shape my network traffic to limit certain content, that would be a bonus...

My network uses Brocade big iron switches.

Thank you for your help.
0
Comment
Question by:Stephen York
  • 4
  • 2
7 Comments
 
LVL 13

Expert Comment

by:kdearing
ID: 35095380
You're looking for a good network monitoring package.
The following link has many:
http://www.experts-exchange.com/Software/System_Utilities/Q_26748566.html?cid=748#a34841205
0
 
LVL 1

Author Comment

by:Stephen York
ID: 35097735
Do you have any preferences?  Have you used What's Up Gold?
0
 
LVL 13

Accepted Solution

by:
kdearing earned 500 total points
ID: 35100247
I've used What's Up Gold, SpiceWorks, and Wireshark.
Alot of experts here love PRTG
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 1

Author Comment

by:Stephen York
ID: 35128299
We will look at WUG and PRTG.  Both have free trials and both can be cost effective for me.  Thank you for your suggestions and help!
0
 
LVL 1

Author Closing Comment

by:Stephen York
ID: 35128304
THANX!!!!!!!!!
0
 

Expert Comment

by:telebec
ID: 40335605
I have a script I created that blocks write access to a certain part of the user registry. Ultrasurf needs to be able set it's own address as a proxy in windows. My blog explains it in more detail http://www.chrisleblanc.org/block-ultrasurf-workstation-level-windows/
0
 
LVL 1

Author Comment

by:Stephen York
ID: 40336432
Interesting - thanx.  My question was really beyond just Ultrasurf, but it was part of my problem...

For the major proxy avoidance tools, after a little observation of real traffic on our network and my firewall, and then running the many versions of Ultrasurf and some of its brothers, we found that Ultrasurf and kin tends to use netblocks from and Asian provider, Hurricane Electric, to stash their moving server IP targets...  nothing good seems to come from there so we simply black-list entire blocks of the netblocks from that vendor and Ultrasurf does not give the illusion of not working, it just doesn't work.  The only complaints that I have had since doing this is from some of my students... <<Insert evil giggle and/or smirk here ...>>  Way easier than playing with so many other things to stop the stupidity.  It is not foolproof, but I employ other means to help bolster my security and tighten the use of my network bandwidth to be more oriented towards education...  I really have so many other better things to do than play spy versus spy, but this is part of the job...
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
These days, all we hear about hacktivists took down so and so websites and retrieved thousands of user’s data. One of the techniques to get unauthorized access to database is by performing SQL injection. This article is quite lengthy which gives bas…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now