OpenSEC Picks

Iptraf - nice curses-based network monitor with lots of pretty screens

Ntop - a Unix tool that shows the network usage, similar to what the popular top Unix command does. Has an interactive mode and a web mode for greater functionality and options, shows network traffic sorted according to various criteria, displays traffic statistics, shows IP traffic distribution among the various protocols, analyses IP traffic and sorts it according to the source/destination, displays IP Traffic Subnet matrix (who's talking to who?), reports IP protocol usage sorted by protocol type.

Other Tools

Bandmin - a simple set of perl scripts designed to record and log ip accouting data. It can also display the data that it collects in a set of html pages. Bandmin currently has support for ipchains, UserIPAcct, ipfwadm, ipf, and ipfw.

Ipfm - a bandwidth analysis tool, that measures how much bandwidth specified hosts use on their Internet link

Ipac - an ip accounting package for linux. It collects, summarizes and nicely displays ip accounting data. The output of ipac can be a simple ascii table, an ascii graph or even gif pictures with graphs, showing traffic progression.

Ipmeter - IPmeter is a network usage metering and billing application for IP traffic. The IPmeter system integrates network flows from metering nodes and uses this transaction data to generate graphical usage reports

Karpski - another gtk+ based monitor

Netwatch - monitors ethernets for hosts, packet counts, protocols and displays in ncurses format with colors indicating hosts activity (Red current / Yellow > 1min / Green > 5min / Blue > 30min), provides an ethernet "top" program for isolating high bandwidth hosts, allows selection of individual hosts (Remote or Local) and monitors the transmissions, provides Router statistics using passive monitoring (rather than querying the router box itself), much more.

Traffic-vis - a suite of tools to help determine which hosts have been communicating on an IP network, with whom they have been communicating and the volume of communication taking place on a host by host basis. Reports can be generated in ASCII and/or HTML format. traffic-vis can also generate Postscript(tm) and GIF charts showing which hosts have communicated with each other.