What should I do if psad catches a scan against my system?
Nmap is freely available on the internet and so anyone who wants to port scan your machine can, and they can do it quite effectively. However the vast majority of such scans are relatively harmless, especially if 1) the act of stopping them also allows you to detect them (this is the method employed by psad), and 2) the person running the scan is one of the k1dd13s. If you receive repeated scans from a particular IP, then you can use the whois information in the psad alert to determine who owns the IP and contact them directly (keep in mind of course that scans may be spoofed).
Related Questions
- Does the System Analysis step in the RSS 2011 Full Restore feature scan all snapshots listed or just the first one on the list?
- Can HP File System Viewer scan NetAppĀ® filers and remotely mounted Network Attached Storage (NAS) volumes?
- What are the different types of optical scan voting system models?