Great Circle Associates Firewalls
(October 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: IP-->Person Translation
From: David Kennedy <76702 . 3557 @ CompuServe . COM>
Date: 24 Oct 96 02:38:55 EDT
To: Firewalls <firewalls @ greatcircle . com>

>>In a recent attack by a person at a university, we were able to
>>determine the  IP address, which was at a university, but could
>>not establish who was  responsible. (The individual was in a
>>pool of computers that they could log on  to). Is there a way
>>to determine which student was responsible? 

I think you're stuck with whatever the site is using for security/logging.  We
worked with a client a few months ago on a similar EDU problem, but the EDU used
Kerberos and other granular logging which allowed _them_ to identify the
student.  (Don't know what happened, the client and the EDU worked it out w/o
our involvement.)

I suppose if you're quick you could ask for the campus cops to take latent
prints from the keys.  Yeah, right....

Dave Kennedy CISSP Dir Research, Nat'l Computer Security Assoc 
(ex-cop too)



Follow-Ups:
Indexed By Date Previous: Re: devnull
From: somebody @ tempest . ashd . com
Next: Re: SecurID algorithm???
From: dvv @ sprint . net (Dima Volodin)
Indexed By Thread Previous: Re: digital firewall
From: maass @ thinkfish . rhein-main . de (Joerg Maass & Teresa Storrie-Maass)
Next: Re: IP-->Person Translation
From: Bob Beck <beck @ obtuse . com>

Google
 
Search Internet Search www.greatcircle.com