passive monitoring will work best against active ones, look into RNA (Realtime network awarenes) by sourcefire, or you could modify a program such as p0f to do your needs.