Talk With an Expert

Reporting Incidents to an ISP with BlackICE ClearICE Report Utility and the Importance of Submitting Firewall Logs to the Dshield.org Project

Reporting Incidents to an ISP with BlackICE ClearICE Report Utility and the Importance of Submitting Firewall Logs to the Dshield.org Project (PDF, 2.76MB)Published: 09 Mar, 2004
Created by:
Victor Arnaud

This practical has two objectives: guide users of BlackICE to report incidents to their ISPs (using ClearICE Report Utility) and show users the importance of submitting firewall logs to the dshield.org project. Since the installation of BlackICE does not require much work on a single workstation, I will assume that it's already installed and start from the incident itself, passing through the BlackICE's alert, blocking the intruder to avoid his activities and working with ClearICE to create an useful report to the attacker's ISP to help them track the malicious user. Considering that all computers on the Internet are targets, you could help information security professionals and systems administrators. Submitting your firewall logs to the Dshield.org project, you help administrators and users all around the world to discover new trends in activities (anomalous and / or malicious) and to prepare better firewall rules. If more and more users and administrators submit their logs to dshield.org, their database will become bigger and the trends discovered easily. Also, firewall rules created based on their analysis will be more accurate.