Hi everyone; Almost everyday we have several attacks ranging from all port scans to spoof attacks against our ISA servers. I asked our ISP to help me identify the attackers using their IPs, but they replied " you have to identify the real attacks from background noise first ". could you help me with this problem and is there such a problem with ISA detecting background noise as attacks? if yes, how could I recognize the real attacks and what type of action could I take against them? thank you, Farshad