You could definitely use Security Onion's tools for that. The full SO distribution is a little bit overkill for that. You could run YAF ([1]) on a box attached to a mirror port to log IP headers and then periodically check it against a tracker.
NetFlow or VPC Flow Logs (in AWS) would work just as well for this also.