-->
Firewall Dashboard Daily Report
Report Created on 19/02/2006 at 11:05 AM for 18/02/2006
 

Executive Dashboard



Connection Attempt Timeline


Protocol Usage

Protocol Usage Count
tcp900
udp75
icmp:8:015
1

SBS RWW Usage Timeline


Top Sources of Attack

Attack Source # of Attacks Additional Information
70.78.80.10667Country: Canada
70.78.123.5256Country: Canada
70.78.102.3750Country: Canada
70.78.80.10632Country: Canada
70.78.123.11125Country: Canada
70.78.94.7320Country: Canada
70.78.85.5816Country: Canada
70.78.123.11115Country: Canada
70.78.80.10613Country: Canada
70.78.123.11111Country: Canada

Top Sources of Connection

Source # of Hits Port Additional Information
84.86.121.222100smtp (25)Country: Netherlands
64.251.84.5584smtp (25)Country: Canada
70.78.82.25448ntp (123)Country: Canada
200.121.10.596smtp (25)Country: Peru
68.118.22.1066smtp (25)Country: United States
70.78.82.2536https (443)Country: Canada
222.255.121.1364smtp (25)Country: Vietnam
200.216.70.1464smtp (25)Country: Brazil
200.127.45.472smtp (25)Country: Argentina
219.140.232.452smtp (25)Country: China

Top Ports Attacked

Port # of Attacks Description
microsoft-ds (445)219Microsoft Domain Service, now called Common Internet File Sharing, used for SMB file and print sharing. Virtually all traffic to this port from foreign hosts should be considered hostile. This port should be firewalled in both directions to prevent attacks and information leakage.
rpc (135)156Microsoft Remote Procedure call, used for application procedure calls across the network. Virtually all traffic to this port from foreign hosts should be considered hostile. This port should be firewalled in both directions to prevent attacks and information leakage such as account names and passwords.
netbios-ssn (139)150NetBIOS Session Service, used by SMB file and print sharing. Virtually all traffic to this port from foreign hosts should be considered hostile. This port should be firewalled in both directions to prevent attacks.
netbios-ns (137)19NetBIOS Name service, used by SMB file and print sharing. Virtually all traffic to this port from foreign hosts should be considered hostile. This port should be firewalled in both directions to prevent attacks.
smtp (25)11This service is used to transfer email to servers from clients or other servers.
ms-sql-s (1433)10Server port for Microsoft SQL Server, used by clients to connect to and access database. Most traffic to this port from foreign hosts should be considered hostile.
ms-sql-m (1434)6Monitoring port for Microsoft SQL Server. Most traffic to this port from foreign hosts should be considered hostile.
Port 72126
ssh (22)5This service offers the secure shell (SSH) protocol. SSH scanning for default and weak user account and password combinations is extremely common on the Internet.
Port 10251This service allows the Microsoft Task Scheduler to use RPC. Virtually all traffic to this port from foreign hosts should be considered hostile. This port should be firewalled in both directions to prevent attacks by trojans such as NetSpy and Fraggle Rock.

Top Services Used

Port Connections Description
smtp (25)322This service is used to transfer email to servers from clients or other servers.
ntp (123)48Network Time Protocol provides time synchronization for workstations and servers. Most traffic to this port from foreign hosts should be considered hostile.
https (443)8The HTTPS service offers web browser clients the ability to surf the world wide web (www) securely with SSL encryption.
dns (53)2The Domain Name Server (DNS) provides mappings of domain names such as www.scorpionsoft.com to IP addresses. A good percentage of incoming DNS traffic may be considered hostile, unless you are offering DNS services to the Internet.

Top Service Usage Timeline