The TAMU security package: an ongoing response to internet intruders in an academic environment
David R. Safford, Douglas Lee Schales, David K. Hess · 1993
Texas A&M University (TAMU) UNIX computers came under coordinated attack in August 1992 from an organized group of internet crackers. This package of security tools represents the results of over seven months of development and testing of the software currently being used to protect the estimated 12,000 networked devices at TAMU (of which roughly 5,000 are IP devices). This package includes three related sets of tools: "drawbridge," a powerful bridging filter package; "tiger," a set of easy to use yet thorough machine checking programs; and "netlog," a set of intrusion detection network monitoring programs. 2. Introduction A Brief History of the Incidents On Tuesday, 25 August 1992, the Texas A&M University Supercomputer Center (TAMUSC) was notified by the Ohio Supercomputer Center that a specific Texas A&M University (TAMU) machine was being used to attack one of their computers over the internet. The local machine turned out to be a Sun workstation in a faculty member's office. Un...