From ForensicsWiki
Jump to: navigation, search


argus is a network flow monitor that is used to establish network activity audits. The audits are the basis of Network Forensics for many universities and corporations, providing data mining for historical network activity. Many sites use contemporary IDS technology like snort and/or Bro to generate events and alarms, and then use the Argus network audit data to provide context for those alarms to decide if the alarms are real problems. In many DIY efforts, snort, Bro and argus run on the same high performance device. The audit data that Argus generates is great for network forensics, non-repudiation, network asset and service inventory, behavioral baselining of server and client relationships, detecting very slow scans, and supporting Zero day events. The network transaction audit data that Argus generates has also been used for a wide range of other tasks including Network Billing and Accounting, Operations Management and Performance Analysis.

Argus uses libpcap and it has been ported to virtually every Unix platform, OpenWRT and on Win32 using Cygwin.

Argus/Ra 3.0.8 Installation Instructions

The Argus/Ra packages installed when using apt-get install are the old 2.0.6 versions, which may have problems with filter-expressions.

In order to build Argus/Ra 3.0.8 on your UNIX machine follow these commands/steps:

NOTE: If you already have a different version of argus/ra installed (e.g., if you installed v2.0.6 using apt-get install), you’ll likely need to rename/remove the “/etc/ra.conf” file or else you’ll get a syntax error when trying to run ra. I just renamed it using the following command (to keep a backup just in case):

  • cd /etc/
  • mv ra.conf ra.conf.bak

External Links

See Also