210 likes | 317 Views
A nalysis C onsole for I ntrusion D atabases. Roy. Description. ACID. Objective. Setup ACID, MySQL, Snort Super alert Analyzer Performance Benchmarking of ACID. About ACID. Query-builder and search interface. Chart and statistics generation. Packet viewer (decoder). Alert management.
E N D
Description ACID
Objective • Setup ACID, MySQL, Snort • Super alert Analyzer • Performance Benchmarking of ACID
About ACID Query-builder and search interface Chart and statistics generation Packet viewer (decoder) Alert management Centralize control
System overview • ACID+Snort+MySQL ACID
Prerequisites • A web server • Package: Apache Server • Version: 1.3.*+ • Homepage: http://www.apache.org/ • PHP access database API • Package: ADODB • Homepage: http://php.weblogs.com/adodb/ • Package: PHPlot • Homepage: http://www.phplot.com • Package: JPGraph • Homepage: http://www.aditus.nu/jpgraph/ • Package: GD • Homepage: http://www.boutell.com/gd/ • A database • Package: MySQL • Version: 3.23.x+ • Homepage: http://www.mysql.com/ • A mechanism • Package: Snort • Version: 1.7+ • Homepage: http://www.snort.org/ • Package: PHP • Version: 4.0.4+ • Homepage: http://www.php.net/
Install ACID and snort • Download ACID • http://www.andrew.cmu.edu/user/rdanyliw/snort/snortacid.html • Decompress acid-0.9.6b23.tar.gz • Move ACID to your web directory
Setting up the database in MySQL • Create database • Create user and assign privilege • Create snort tables
Modify ACID config files • Edit acid_conf.php
Connect to sensor manager • Open http://192.168.1.101/acid/acid_conf.php
Setup snort output module • Edit /etc/snort/snort.conf
Test environment 三暝三日…
Enjoy the results • Open http://192.168.1.101/acid/
More analysis • 5 most frequent alerts (alert listing) • 15 most frequent alerts (unique source) • Time profile of alerts • Last 24 hours • Last 72 hours
Performance Benchmarking of ACID (Page loading time) • Host: Intel Mobile 800Mhz, 256 MB RAM • OS: Linux 2.2.16-22 • Apache: 1.3.19 • PHP: 4.0.5 • MySQL: 3.23.32 • PostgreSQL:7.1.2 • DB schema: v102 • ACID: 0.9.6b10 - 0.9.6b13
Reference • Performance Benchmarking of ACID • http://www.andrew.cmu.edu/user/rdanyliw/snort/perf/acid_perf.html • NIST Intrusion Detection System
Appendix A • Passive Ethernet Tap IDS Traffic in Traffic out http://www.snort.org/docs/tap/