Forum Moderators: DixonJones

Message Too Old, No Replies

Are logs reliable?

statistics for logs are good untill...

         

AlexPar

6:04 pm on Aug 18, 2003 (gmt 0)

10+ Year Member



...a one or more "nice" persons with anonimized randomly generated proxy wants to visit our site.
I have personally nothing against anonimity and using proxies. But at last using anonimity proxies with randomly generated few IP numbers during one second period is a nightmare for analyzing logs. I think there should be a bit netiquette.
The same about spoofed IP addresses.

I see a few ways of resolving this problem:
1. Find a v. good heuristic software for analizing raw logs
(maybe somebody knows about it? - please),
2. Identify IP to the end (it is really possible?) or identify visiting IP as spoofed or using multiple IP proxies and identify one visit using cookies/sesions etc?
3. Identify problematic IP and redirect them to a specified error page.

I am writing and testing scripts but despite of the fact that I reached some goals like nice probability of identification of a bunch of IP numbers as one visit - I am still on early start of my work.

I will apperciate any help and suggestions.
Thank you.

Sorry for my language mistakes - english isn't my native.

----------------------------
Don't tell I am paranoid - I know I am.

aspdaddy

6:29 pm on Aug 18, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Another way you have not listed is to forget logfiles & track at the application level using session logic.

I like approach no.1 best. Theres been a lot of research in this area and is still ongoing. I did a thesis on the subject myself and am still clueless :) One area that may be of interest to you is host munging. I have stickied you some info.

Good Luck.

claus

8:13 pm on Aug 18, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



>> host munging

I'm just curious, what is that?

/claus

AlexPar

12:06 am on Aug 19, 2003 (gmt 0)

10+ Year Member



Thanks for reply aspdaddy. Your have my answer in your box.
And yes of course - session logic - I think is the must be modul among others.
Hmm - I am not a big fan of Java but Java login or Java applet to discover real IP...?
And again - nothing against anonimity when it is used in good faith. Anyway I have self made/verificate fresh proxies list (anonymous and high anonymous ones only), about 750 entries form whole world. I use it in my database to filter the proxies I found take a big part in all attempts to hack site/server. (plus some specific IPs I love much). If you think it can be usefull for you - how can it be published?
If you find I write something stiupid - sorry me - I am really tired. (and corredt me, pls)

Sorry for my language mistakes - english isn't my native.

----------------------------
Don't tell I am paranoid - I know I am.