|
您好,我们宿舍是用ADSL的,十一个人一起用,猫的是实达的ADSL2110EH,ROUTER4.8,以前用的时候是一点问题都没有的(开路由方式上网),现在老是断流,我已经改了猫的端口,做一个BIMAP的全映射,开了防火墙,可是还是有问题,上网时断时不断.在防火墙的日志中有下面的记录,可惜我不明白是什么意思,请指教.还有如何判断我们内网的机子哪台是有病毒,我试过用BLACKICE装在我的电脑来看有什么攻击,可是就看不到有内网来攻击我的机子,请问还有什么好的软件来监测吗?
15:57:21 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.94.253, Dst:219.137.169.77, Prot:TCP , DPort:135 , Intf: ppp-0, ScanCnt:11173
15:56:49 Elapsed Time
Port Scan Type- ACK scan, Src:83.140.65.2, Dst:219.137.169.77, Prot:TCP , DPort:50622, Intf: ppp-0, ScanCnt:3924
15:49:27 Elapsed Time
Port Scan Type- RST scan, Src:219.129.21.175, Dst:219.137.169.77, Prot:TCP , DPort:50172, Intf: ppp-0, ScanCnt:94
15:41:50 Elapsed Time
Port Scan Type- SYNACK Scan, Src:61.135.134.92, Dst:219.137.169.77, Prot:TCP , DPort:50026, Intf: ppp-0, ScanCnt:34
15:37:55 Elapsed Time
Port Scan Type- ICMP Scan, Src:221.122.45.9, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:514
15:35:37 Elapsed Time
ViolationType- SYN DOS, Src:61.135.132.168, Dst:219.137.169.77, Prot:TCP , SPort: 80, DPort:50780, Intf: ppp-0, ViolationCnt:26
SessDeleted:26
15:27:21 Elapsed Time
Port Scan Type-TCP Session scan, Src:218.20.227.163, Dst:219.137.169.77, Prot:TCP , DPort:24642, Intf: ppp-0, ScanCnt:1180
15:26:49 Elapsed Time
Port Scan Type- ACK scan, Src:192.168.1.6, Dst:219.137.2.84, Prot:TCP , DPort:554 , Intf: eth-0, ScanCnt:917
15:19:26 Elapsed Time
Port Scan Type- RST scan, Src:65.54.179.192, Dst:219.137.169.77, Prot:TCP , DPort:50296, Intf: ppp-0, ScanCnt:80
15:7:48 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.137.252.139, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:410
15:1:47 Elapsed Time
Port Scan Type- SYNACK Scan, Src:61.135.134.86, Dst:219.137.169.77, Prot:TCP , DPort:50529, Intf: ppp-0, ScanCnt:2
15:0:38 Elapsed Time
ViolationType- SYN DOS, Src:192.168.1.6, Dst:218.75.1.212, Prot:TCP , SPort: 1316, DPort:16881, Intf: eth-0, ViolationCnt:170
SessDeleted:24
14:57:19 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.169.231, Dst:219.137.169.77, Prot:TCP , DPort:135 , Intf: ppp-0, ScanCnt:149
14:56:48 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
14:37:45 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.137.231.9, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:388
14:27:1 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.169.231, Dst:219.137.169.77, Prot:TCP , DPort:1025 , Intf: ppp-0, ScanCnt:133
14:23:32 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:12
14:7:40 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.137.247.43, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:336
14:0:36 Elapsed Time
Port Scan Type- RST scan, Src:60.35.56.150, Dst:219.137.169.77, Prot:TCP , DPort:8587 , Intf: ppp-0, ScanCnt:0
13:56:55 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.93.26, Dst:219.137.169.77, Prot:TCP , DPort:445 , Intf: ppp-0, ScanCnt:53
13:50:17 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
13:37:36 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.137.39.181, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:335
13:25:12 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.237.113, Dst:219.137.169.77, Prot:TCP , DPort:135 , Intf: ppp-0, ScanCnt:44
13:20:21 Elapsed Time
Port Scan Type- RST scan, Src:192.168.0.2, Dst:219.137.169.77, Prot:TCP , DPort:8587 , Intf: ppp-0, ScanCnt:0
13:17:2 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
13:7:31 Elapsed Time
Port Scan Type- ICMP Scan, Src:221.0.31.127, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:256
12:55:7 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.108.189, Dst:219.137.169.77, Prot:TCP , DPort:445 , Intf: ppp-0, ScanCnt:23
12:43:46 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
12:37:30 Elapsed Time
Port Scan Type- ICMP Scan, Src:218.7.120.119, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:169
12:24:2 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.112.190.191, Dst:219.137.169.77, Prot:TCP , DPort:2745 , Intf: ppp-0, ScanCnt:3
12:10:31 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
12:7:14 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.137.76.196, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:132
11:44:4 Elapsed Time
Port Scan Type- RST scan, Src:70.16.235.123, Dst:219.137.169.77, Prot:TCP , DPort:445 , Intf: ppp-0, ScanCnt:1
11:41:0 Elapsed Time
Port Scan Type-TCP Session scan, Src:221.208.50.58, Dst:219.137.169.77, Prot:TCP , DPort:8587 , Intf: ppp-0, ScanCnt:0
11:37:16 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
11:37:6 Elapsed Time
Port Scan Type- ICMP Scan, Src:218.65.113.10, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:121
11:7:4 Elapsed Time
Port Scan Type- ICMP Scan, Src:65.88.99.123, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:78
11:4:5 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
10:37:2 Elapsed Time
Port Scan Type- ICMP Scan, Src:222.65.100.243, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:104
10:30:50 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
10:20:28 Elapsed Time
Port Scan Type-TCP Session scan, Src:218.58.91.118, Dst:219.137.169.77, Prot:TCP , DPort:8587 , Intf: ppp
10:4:36 Elapsed Time
Port Scan Type- ICMP Scan, Src:60.35.56.150, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:112
9:57:35 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
9:50:15 Elapsed Time
Port Scan Type-TCP Session scan, Src:218.104.195.83, Dst:219.137.169.77, Prot:TCP , DPort:18023, Intf: ppp-0, ScanCnt:10
9:34:24 Elapsed Time
Port Scan Type- ICMP Scan, Src:69.196.35.23, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:97
9:24:19 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
9:4:24 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.94.122.106, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:105
8:53:29 Elapsed Time
Port Scan Type-TCP Session scan, Src:218.70.159.1, Dst:219.137.169.77, Prot:TCP , DPort:8587 , Intf: ppp-0, ScanCnt:3
8:51:4 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
8:34:7 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.137.190.204, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:113
8:17:49 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
8:3:44 Elapsed Time
Port Scan Type- ICMP Scan, Src:218.0.211.209, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:142
7:44:33 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:13
7:35:13 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.158.178, Dst:219.137.169.77, Prot:TCP , DPort:445 , Intf: ppp-0, ScanCnt:8
7:33:40 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.157.145.135, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:150
7:19:27 Elapsed Time
Port Scan Type- RST scan, Src:218.83.227.151, Dst:219.137.169.77, Prot:TCP , DPort:8587 , Intf: ppp-0, ScanCnt:1
7:11:18 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:12
7:3:40 Elapsed Time
Port Scan Type- ICMP Scan, Src:218.162.2.33, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:194
7:3:28 Elapsed Time
Port Scan Type-TCP Session scan, Src:221.233.108.148, Dst:219.137.169.77, Prot:TCP , DPort:8587 , Intf: ppp-0, ScanCnt:11
6:38:3 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:15
6:32:46 Elapsed Time
Port Scan Type-TCP Session scan, Src:218.81.219.242, Dst:219.137.169.77, Prot:TCP , DPort:24642, Intf: ppp-0, ScanCnt:22
6:32:43 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.137.122.149, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:234
6:31:39 Elapsed Time
Port Scan Type- RST scan, Src:211.158.68.206, Dst:219.137.169.77, Prot:TCP , DPort:50565, Intf: ppp-0, ScanCnt:4
6:4:47 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:31
6:2:37 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.139.201.190, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:306
6:1:22 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.114.237, Dst:219.137.169.77, Prot:TCP , DPort:139 , Intf: ppp-0, ScanCnt:1107
5:45:58 Elapsed Time
ViolationType- SYN DOS, Src:192.168.1.11, Dst:218.164.54.230, Prot:TCP , SPort: 2166, DPort:18695, Intf: eth-0, ViolationCnt:2
SessDeleted:26
5:45:39 Elapsed Time
Port Scan Type- SYNACK Scan, Src:24.150.136.82, Dst:219.137.169.77, Prot:TCP , DPort:50635, Intf: ppp-0, ScanCnt:56
5:39:39 Elapsed Time
ViolationType- SingleHost DOS, IP Address:192.168.1.11, Intf: (null)
5:33:55 Elapsed Time
Port Scan Type- RST scan, Src:211.30.114.34, Dst:219.137.169.77, Prot:TCP , DPort:50059, Intf: ppp-0, ScanCnt:3
5:33:40 Elapsed Time
Port Scan Type- ACK scan, Src:218.69.230.76, Dst:219.137.169.77, Prot:TCP , DPort:50344, Intf: ppp-0, ScanCnt:29
5:32:30 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.130.88.66, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:384
5:31:4 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.62.219, Dst:219.137.169.77, Prot:TCP , DPort:445 , Intf: ppp-0, ScanCnt:520
5:8:34 Elapsed Time
ViolationType- SingleHost DOS, IP Address:192.168.1.11, Intf: (null)
5:3:7 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:563
5:2:29 Elapsed Time
Port Scan Type- ICMP Scan, Src:221.202.235.74, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:397
5:0:44 Elapsed Time
Port Scan Type-TCP Session scan, Src:192.168.1.11, Dst:220.173.88.112, Prot:TCP , DPort:9920 , Intf: eth-0, ScanCnt:899
4:48:26 Elapsed Time
Port Scan Type- RST scan, Src:219.133.47.237, Dst:219.137.169.77, Prot:TCP , DPort:50333, Intf: ppp-0, ScanCnt:20
4:44:37 Elapsed Time
ViolationType- SYN DOS, Src:192.168.1.11, Dst:218.83.203.56, Prot:TCP , SPort: 4264, DPort:16713, Intf: eth-0, ViolationCnt:1
SessDeleted:35
4:37:44 Elapsed Time
ViolationType- SingleHost DOS, IP Address:192.168.1.11, Intf: (null)
4:32:23 Elapsed Time
Port Scan Type- ICMP Scan, Src:218.102.180.42, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:390
4:31:21 Elapsed Time
Port Scan Type- ACK scan, Src:221.12.90.43, Dst:219.137.169.77, Prot:TCP , DPort:50861, Intf: ppp-0, ScanCnt:576
4:30:31 Elapsed Time
Port Scan Type- SYNACK Scan, Src:202.104.129.245, Dst:219.137.169.77, Prot:TCP , DPort:50789, Intf: ppp-0, ScanCnt:7
4:30:29 Elapsed Time
Port Scan Type-TCP Session sc
4:16:7 Elapsed Time
Port Scan Type- RST scan, Src:192.168.1.11, Dst:221.236.11.25, Prot:TCP , DPort:443 , Intf: eth-0, ScanCnt:3
4:13:55 Elapsed Time
ViolationType- SYN DOS, Src:192.168.1.11, Dst:65.27.177.51, Prot:TCP , SPort: 2952, DPort:18443, Intf: eth-0, ViolationCnt:5
SessDeleted:27
4:7:42 Elapsed Time
ViolationType- SingleHost DOS, IP Address:192.168.1.11, Intf: (null)
4:2:19 Elapsed Time
Port Scan Type- ICMP Scan, Src:218.72.25.38, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:470
4:1:21 Elapsed Time
Port Scan Type- ACK scan, Src:209.61.254.143, Dst:219.137.169.77, Prot:TCP , DPort:50950, Intf: ppp-0, ScanCnt:36
4:0:29 Elapsed Time
Port Scan Type-TCP Session scan, Src:220.211.87.62, Dst:219.137.169.77, Prot:TCP , DPort:8587 , Intf: ppp-0, ScanCnt:717
3:55:42 Elapsed Time
Port Scan Type- SYNACK Scan, Src:218.69.205.192, Dst:219.137.169.77, Prot:TCP , DPort:50878, Intf: ppp-0, ScanCnt:8
3:41:41 Elapsed Time
Port Scan Type- RST scan, Src:211.30.114.34, Dst:219.137.169.77, Prot:TCP , DPort:50213, Intf: ppp-0, ScanCnt:9
3:34:6 Elapsed Time
ViolationType- SYN DOS, Src:192.168.1.11, Dst:61.51.56.9, Prot:TCP , SPort: 2086, DPort:1881 , Intf: eth-0, ViolationCnt:12
SessDeleted:37
3:32:16 Elapsed Time
Port Scan Type- ICMP Scan, Src:83.213.88.186, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:531
3:31:29 Elapsed Time
Port Scan Type-Fragmentation Scan, Src:61.54.81.7, Dst:219.137.169.77, Prot:TCP , DPort:1618 , Intf: ppp-0, ScanCnt:0
3:30:46 Elapsed Time
Port Scan Type- ACK scan, Src:218.81.191.248, Dst:219.137.169.77, Prot:TCP , DPort:50613, Intf: ppp-0, ScanCnt:92
3:30:23 Elapsed Time
Port Scan Type-TCP Session scan, Src:192.168.1.11, Dst:220.172.205.179, Prot:TCP , DPort:10003, Intf: eth-0, ScanCnt:971
3:18:24 Elapsed Time
Port Scan Type- SYNACK Scan, Src:218.30.106.33, Dst:219.137.169.77, Prot:TCP , DPort:50667, Intf: ppp-0, ScanCnt:17
3:5:3 Elapsed Time
Port Scan Type- RST scan, Src:218.18.71.220, Dst:219.137.169.77, Prot:TCP , DPort:50131, Intf: ppp-0, ScanCnt:37
3:2:53 Elapsed Time
ViolationType- SYN DOS, Src:192.168.1.11, Dst:61.144.70.24, Prot:TCP , SPort: 1211, DPort:8868 , Intf: eth-0, ViolationCnt:86
SessDeleted:28
3:2:16 Elapsed Time
Port Scan Type- ICMP Scan, Src:219.137.248.164, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:554
3:0:22 Elapsed Time
Port Scan Type-TCP Session scan, Src:219.137.64.244, Dst:219.137.169.77, Prot:TCP , DPort:135 , Intf: ppp-0, ScanCnt:1641
3:0:18 Elapsed Time
Port Scan Type- ACK scan, Src:192.168.1.10, Dst:61.129.48.130, Prot:TCP , DPort:80 , Intf: eth-0, ScanCnt:696
2:42:58 Elapsed Time
Port Scan Type-Fragmentation Scan, Src:192.168.4.85, Dst:219.137.169.77, Prot:TCP , DPort:8587 , Intf: ppp-0, ScanCnt:0
2:35:39 Elapsed Time
Port Scan Type- SYNACK Scan, Src:202.116.16
2:34:26 Elapsed Time
Port Scan Type- RST scan, Src:192.168.1.11, Dst:219.133.38.21, Prot:TCP , DPort:8000 , Intf: eth-0, ScanCnt:82
2:32:50 Elapsed Time
ViolationType- SYN DOS, Src:192.168.1.11, Dst:220.186.56.205, Prot:TCP , SPort: 3796, DPort:17750, Intf: eth-0, ViolationCnt:1843
SessDeleted:16
2:32:14 Elapsed Time
Port Scan Type- ICMP Scan, Src:81.44.198.249, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:526
2:30:22 Elapsed Time
Port Scan Type-TCP Session scan, Src:192.168.1.11, Dst:61.132.91.2, Prot:TCP , DPort:15478, Intf: eth-0, ScanCnt:4985
2:30:6 Elapsed Time
Port Scan Type- ACK scan, Src:219.95.32.204, Dst:219.137.169.77, Prot:TCP , DPort:50520, Intf: ppp-0, ScanCnt:4423
2:3:45 Elapsed Time
Port Scan Type- SYNACK Scan, Src:221.12.108.93, Dst:219.137.169.77, Prot:TCP , DPort:50072, Intf: ppp-0, ScanCnt:854
2:3:29 Elapsed Time
Port Scan Type- RST scan, Src:202.103.134.123, Dst:219.137.169.77, Prot:TCP , DPort:50267, Intf: ppp-0, ScanCnt:286
2:2:27 Elapsed Time
ViolationType- SYN DOS, Src:222.135.88.175, Dst:219.137.169.77, Prot:TCP , SPort:17556, DPort:18023, Intf: ppp-0, ViolationCnt:11451
SessDeleted:36
2:2:11 Elapsed Time
Port Scan Type- ICMP Scan, Src:211.162.111.49, Dst:219.137.169.77, Prot:TCP , Intf: ppp-0, ScanCnt:400
|
|