cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
472
Views
0
Helpful
1
Replies

Automated responsible party notification from IDS?

stbob
Level 1
Level 1

Has anyone heard of / developed scripts for automated notification of third party responsible admininistrators (i.e., whois lookup of offending IP address, abuse.net lookup, etc.) from IDS logs? Seems to me this would drastically increase the amount of work done by a security department and the amount of time free for less automatable tasks.

I'd like to send out canned verbiage indicating the date, time, source IP and signature description, standard legal warnings, etc., and an especially rude message to administrators who still have Code Red-infected machines running on their networks.

1 Reply 1

dlac455
Level 1
Level 1