I put Snort on my system last night and it's starting to detect things,
I need help understanding the output, does the following mean that my
system is issueing a port scan or does it mean that someone is scanning
me? (the xx.xxx.xxx.65 is my IP address)
04/08-12:57:38.253334 [**] [100:1:1] spp_portscan: PORTSCAN DETECTED from xx.xxx.xxx.65 (THRESHOLD 4 connections exceeded in 4 seconds) [**]
04/08-12:57:44.885436 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 6 connections across 6 hosts: TCP(6), UDP(0) [**]
04/08-12:57:57.883683 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-12:58:15.442163 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 2 connections across 2 hosts: TCP(2), UDP(0) [**]
04/08-12:58:55.724257 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-12:59:15.447610 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 2 connections across 2 hosts: TCP(2), UDP(0) [**]
04/08-12:59:19.172129 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:00:15.440175 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 2 connections across 2 hosts: TCP(2), UDP(0) [**]
04/08-13:00:35.742465 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:01:15.447612 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:02:15.454337 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:03:15.461526 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:04:15.895894 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:05:15.489891 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:06:15.484172 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:06:24.481672 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:06:36.481191 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:07:00.480261 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:07:15.497180 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:08:15.499105 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:09:15.520534 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:10:15.529660 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TCP(1), UDP(0) [**]
04/08-13:11:16.444651 [**] [100:2:1] spp_portscan: portscan status from xx.xxx.xxx.65: 1 connections across 1 hosts: TC