positivelaha.blogg.se

Linux network usage by process
Linux network usage by process






In the netstat output you can also see the port opened by a specific process. These may provide indications as to the source of the program or the nature of the tasks it is performing. The netstat command allows to see the connections from and to our current Linux systems and it provides flags that also show which process a specific connection is related to. Examine the process arguments, title and working directory. If it has a consistent cadence (for example if it runs monthly or quarterly), it might be part of a monthly or quarterly business or maintenance process. If this process only manifested recently, it might be part of a new software package. Is this network activity part of an expected workflow for the user who ran the program? Consider the user as identified by the username field. If the destination IP address is remote or external, does it associate with an expected domain, organization or geography? Note: avoid interacting directly with suspected malicious IP addresses. Are these used by normal but infrequent network workflows? Are they expected or unexpected? Here are some possible avenues of investigation: # Investigating Unusual Network Activityĭetection alerts from this rule indicate the presence of network activity from a Linux process for which network activity is rare and unusual.








Linux network usage by process