Monitoring Incoming TCP Connections
script examples
monitoring incoming TCP connections
examples of SystemTap scripts
monitoring incoming TCP connections
monitoring incoming TCP connections
examples of SystemTap scripts
TCP connections (incoming), monitoring
examples of SystemTap scripts
incoming TCP connections, monitoring
examples of SystemTap scripts
This section illustrates how to monitor incoming TCP connections. This task is useful in
identifying any unauthorized, suspicious, or otherwise unwanted network access requests
in real time.
tcp_connections.stp
While is running, it will print out the following information
about any incoming TCP connections accepted by the system in real time:
Current UID
CMD - the command accepting the connection
PID of the command
Port used by the connection
IP address from which the TCP connection originated
Sample Output
UID CMD PID PORT IP_SOURCE
0 sshd 3165 22 10.64.0.227
0 sshd 3165 22 10.64.0.227