back

by bbayles·10y ago·view on hn ↗
You could definitely use Security Onion's tools for that. The full SO distribution is a little bit overkill for that. You could run YAF ([1]) on a box attached to a mirror port to log IP headers and then periodically check it against a tracker.

NetFlow or VPC Flow Logs (in AWS) would work just as well for this also.

[1] http://tools.netsa.cert.org/yaf/index.html