About the White Paper:
Ntop was originally designed as an open source, Web-based traffic measurement and monitoring application that is easy to deploy by network administrators. As ntop has been used for analyzing traffic patters, some users requested facilities for classifying traffic, hence recognizing specific
attacks. In order to address these requests, the authors decided to extend ntop by adding an embedded NDIS (network intrusion-detection system). What makes ntop NIDS unique from other available NDIS is its knowledge of the monitored network. While capturing packets, ntop learns network topology and host relationships (i.e. routers, DNS, networks) and stores this information in a network-knowledge database.
To access this white paper, click on Docs in the left hand nav bar on http://www.ntop.org/ntop.html. |