Full text

Journal of Information System Security
Volume 7, Number 3 (2011)
Pages 215
ISSN 1551-0123
John Week — University of Nevada, Reno, USA
Polina Ivanova — University of Nevada, Reno, USA
Sandy Week — University of Nevada, Reno, USA
Alexander McLeod — University of Nevada, Reno, USA
Information Institute Publishing, Washington DC, USA




On November 2, 1988, Peter Yee at the NASA Ames Research Center sent a note out to the Internet mailing list reporting, "We are currently under attack from an Internet VIRUS!” As these events were unfolding the firewall was starting its rapid evolution. Management often underestimates the importance of sufficient network security. Remarkably, there is little information available for network administrators to use to analyze the valuable data contained in their firewall logs in order to accurately describe threats to their systems. This paper examines 7,478 attacks logged by a small business Internet Service Provider (ISP) hosting 13 domains. On average, 276 attacks occurred per day. About one half of the attacks are the common Windows RPC and SQL Slammer attacks. Slightly less than one half of those attacks came from ten networks and about 25% of those originated from ten hosts. Results suggest what actions can be taken to strengthen small business network security. Results were compared and contrasted with a similar study called Statistical Analysis of Snort Alarms for a Medium-Sized Network recently undertaken by Chantawut and Ghita (2010.)




Network Attacks, Small Business ISP, Origin of Attacks, Time of Attacks, Firewall Data Log




