Features
- A framework which allow to :
- Launching/stopping tools, with different parameters, wherever it is installed on the network.
- Collect data from the tools wherever it is on the network.
- Performing a decision process. The decision process take into account some user's defined rules (what to do), priority settings (priority on the user/user group, IP/network and time) and collected data.
- Helping the user to write rules by providing a rules language.
- Defining a security policy with a web interface.
- Doing alert reporting (web interface).
- Collection of scipts to perform log analysis. Actually the scripts are existing for SQuid.
- Informations and plugins for some tools. Actually we are using mrtg and the last version of rrdtool to perfom the hight level data collection and anomaly detection with low ressource consuming.