Ask Leo! by Leo A. Notenboom

I'm being notified of an intrusion attempt, what should I do?

Search First! Then browse: Categories | Full Archive | By Date | Newsletter

Home » Viruses and Malware » Malware Prevention

Summary: Intrusion attempts are actually common - you'd be surprised at how much internet traffic is due to infected machines trying to infect other machines.

The security on my computer says network traffic from (some IP address) matches the signature of a known attack. does this mean someone tried to hack into my computer and if so, how do i find out who it was?

Yes it does, and no it doesn't.

And finding out who it was it not only difficult, but probably pointless as well.

While it's certainly possible that someone is attempting to break in to your computer, it's really not very likely. By that I mean that unless you present some kind of lucrative target for some reason, there's not likely to be someone out there trying to get at you specifically.

What's more likely is that:

  • There are thousands of infected computers out there

  • They're trying to infect anyone who isn't protected

"Firewalls protect you from these random and unauthorized attempts."

Most viruses work by trying to infect other machines once they've infected yours. They do that through a number of different ways, but the important thing here is that they're simply machines, and they're dumb. They're just looking to infect anyone that they can reach.

If you were to actually look at the traffic on the internet you'd see that a great portion of it is exactly that: infected machines randomly or methodically attempting to reach out and infect other machines.

This is why you need a firewall. Even a NAT router will do. Firewalls protect you from these random and unauthorized attempts.

The great news here, is that it sounds like you already have that in place. It's likely your firewall that's reporting the intrusion attempt.

You could try to track down the infected machine trying to infect you, I suppose. The problem is that with only the IP address you can only get as far as the ISP that provides that machine's internet connection. That's not going to do much for you.

In your shoes, I'd ignore it, knowing that my firewall was protecting me, and get on with my life.

Related:

Helpful? Get new articles weekly by email in my FREE newsletter!

Your Name:
Your Email:


Why Subscribe?

Article C3085 - July 14, 2007

Recent Comments
2 Comments

If you need a great firewall, there is a free one called zone alarm. Go to www.zonealarm.com and download the free one. You can also have a free trial for 15 days of a virus protector but I wouldn't take it. The best virus protector in my opinion is Avg. This is free also and is available at
http://rd.bcentral.com/?ID=4765304&s=149596295
or you can go to www.grisoft.com and try and find it that way.

Posted by: Trevor at July 20, 2007 7:58 PM

OK. I am getting this intrusion attempt. My information says that the attacking computer is my own (I would think that this was the computer that is trying to attack mycomputer). And then i gives another desination attempt. It happens when I'm trying to access the internet. So I'm assuming that my computer is trying to access a site that is not trusted by my firewall. However, I don't recognize the website as one that I've ever attempted to purposely access. So now, it comes up as my homepage and when I try to set my homepage back to the default, it will set it for one try and then it reverts back to the intrusion site. How can I change this? I would like to get into the internet without goin through this routine every time. Thank you

Posted by: Raquel at December 12, 2008 2:54 PM

Post a comment on "I'm being notified of an intrusion attempt, what should I do?":






(Email Address will not be published.)

Remember Me?

By popular demand...
my tip jar
Cuppa Joe
Buy Leo a Latte!

(you may use HTML tags for style)

RSS feed Subscribe to the RSS Feed specifically for comments on this article.

Before commenting, please...

  • Read the article at the top of this page. If your comment shows you didn't, it'll be deleted and ignored.

  • Comment only on this article. Use the Google search box at the top of the page if you have a question about something else.

  • Don't include personal information in the comment. No email addresses. No phone numbers. No physical addresses.

  • Don't spam. Excessive links to unrelated sites within a comment or across multiple comments will cause all such comments to be removed.

  • Don't ask me to recover lost passwords or hacked accounts. I can't, and those comments will be deleted.

  • I can't respond to every comment. And I can't vouch for the accuracy of others who do.

Please wait. Your comment is being processed ...


Question? Ask Leo!