The Poor Man's (or Woman's) Intrusion Detection System
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 

26 lines
700 B

  1. TODO
  2. ====
  3. - trafficctl: wild-card whitelisting. Either just remember "accepts" or use the "*" notation.
  4. - trafficctl: "whole domain" should only change those entries in the group being reported. What about "*".
  5. - should probably convert to use static-linked MySQL client. C++DB has trouble with longterm connections.
  6. - trafficctl: comment field?
  7. BUGS
  8. ====
  9. - The wild card blocks don't seem to be automatically moving DNS
  10. entries into the block list.
  11. IDEAS
  12. =====
  13. - what about drilling down on domains: domain.tld, then expand up
  14. levels if there are more than a couple of entries.
  15. - Some way to browse by workstation traffic
  16. - See hosts that accessed a domain in the lists.