Subsections 3.4.1 msg 3.4.1.1 Format 3.4.2 reference 3.4.2.1 Format 3.4.2.2 Examples 3.4.3 gid 3.4.3.1 Format 3.4.3.2 Example 3.4.4 sid 3.4.4.1 Format 3.4.4.2 Example 3.4.5 rev 3.4.5.1 Format 3.4.5.2 Example 3.4.6 classtype 3.4.6.1 Format 3.4.6.2 Example 3.4.6.3 Warnings 3.4.7 priority 3.4.7.1 Format 3.4.7.2 Examples 3.4.8 metadata 3.4.8.1 Format 3.4.8.2 Examples 3.4.9 General Rule Quick Reference
ã«ã¼ã«ãªãã·ã§ã³ 2.3 ã«ã¼ã«ãªãã·ã§ã³ ã«ã¼ã«ãªãã·ã§ã³ã¯Snort䏿£ä¾µå ¥æ¤ç¥ã¨ã³ã¸ã³ã®å¿èé¨ã§ãåå¼·ãã¨æè»æ§ã« 使ãããããå ¼ãåãã¦ãã¾ãããã¹ã¦ã®Snortã«ã¼ã«ãªãã·ã§ã³ã¯ã»ãã³ãã³ ``;''æåã§åºåããã¾ããã¾ããã«ã¼ã«ãªãã·ã§ã³ã¯ã³ãã³``:''ã§ãã¼ã¯ã¼ãã¨ å¼æ°ãåºåãã¾ãã 2.3.0.1 å©ç¨å¯è½ãªãã¼ã¯ã¼ã msg ã¢ã©ã¼ãããã±ãããã°å ã«ã¡ãã»ã¼ã¸ãåºåãã¾ã logto æ¨æºã®åºåãã¡ã¤ã«ã§ã¯ãªãã¦ã¼ã¶ãæå®ãããã¡ã¤ã«åã«ãã±ãããè¨é²ãã¾ã ttl IPãããã®TTLãã£ã¼ã«ãã®å¤ãæ¤æ»ãã¾ã tos IPãããã®TOSãã£ã¼ã«ãã®å¤ãæ¤æ»ãã¾ã id ç¹å®ã®å¤ã«é¢ãã¦IPãããã®ãã©ã°ã¡ã³ãIDãã£ã¼ã«ããæ¤æ»ãã¾ã ipoption ç¹å®ã®ã³ã¼ãã«é¢ãã¦IP optionãã£ã¼ã«ããç£è¦ãã¾ã fragbits IPãããã®ãã©ã°ã¡ã³ãã¼ã·ã§
ã¯ã©ãã«ã¼ã«ããLinuxãµã¼ãã¼ã¸ã®ä¸æ£ã¢ã¯ã»ã¹ãæ¤ç¥ããã·ã¹ãã (IDS=Intrusion Detection System)ãå°å ¥ããã ããã§ã¯ã䏿£ã¢ã¯ã»ã¹æ¤ç¥ã·ã¹ãã ã«ãããã¯ã¼ã¯åIDSã®Snortãå°å ¥ããã ã¾ããSnortãæ½åºãã䏿£ã¢ã¯ã»ã¹ãã°ãWebãã©ã¦ã¶ä¸ã§ç¢ºèªã§ããããã«ããããã«BASEãå°å ¥ããã ãªããSnortã䏿£ã¢ã¯ã»ã¹ã®å¤æãããããã«åç §ããã«ã¼ã«ãã¡ã¤ã«ã®ææ°åã¯ãOinkmasterãå°å ¥ãã¦èªååããã â»ApacheãMySQLã¤ã³ã¹ãã¼ã«æ¸ã§ããã㨠[root@centos ~]# yum -y install libpcap-develãâãsnortã®RPM使ã«å¿ è¦ãªããã±ã¼ã¸ã¤ã³ã¹ãã¼ã« [root@centos ~]# wget http://dl.snort.org/snort-current/snort-2.8.4
ããã©ã«ãã§ç¡å¹ã«ãªã£ã¦ããã«ã¼ã«ï¼Snort-2.3.3ï¼ # include $RULE_PATH/web-attacks.rules # include $RULE_PATH/backdoor.rules # include $RULE_PATH/shellcode.rules # include $RULE_PATH/policy.rules # include $RULE_PATH/porn.rules # include $RULE_PATH/info.rules # include $RULE_PATH/icmp-info.rules # include $RULE_PATH/chat.rules # include $RULE_PATH/multimedia.rules # include $RULE_PATH/p2p.rules #####################
Libcapã¯å ã å ¥ã£ã¦ãããlibcap-1.10-26-i386 PCREã¯å ã å ¥ã£ã¦ãããpcre-6.6-2.el5_1.7-i386 DAGã®ãªãã¸ããªãã¤ã³ã¹ãã¼ã« # rpm -Uhv http://apt.sw.be/redhat/el5/en/i386/rpmforge/RPMS/rpmforge-release-0.3.6-1.el5.rf.i386.rpm # yum install libnet libnetfilter_conntrack libnetfilter_conntrack-devel Barnyardããã¦ã³ãã¼ããã¦ã¤ã³ã¹ãã¼ã« # wget http://www.snort.org/downloads/74 # tar zxvf barnyard-0.2.0.tar.gz # cd barnyard-0.2.0 # ./configure # ma
IDSã§ããsnortãã¤ã³ã¹ãã¼ã«ããæã®åå¿é²ã§ãã â 使ç¨OS CentOS 5.5 64bit â ãã·ã³ãã¹ãå kurobuti.local â /etc/hostsã®æ å ± 127.0.0.1 kurobuti.local snort localhost.localdomain localhost â snortãã¼ã¸ã§ã³ snort-2.9.0.1 â»ææ°çã¯ä¸è¨URLã§ç¢ºèªãã¦ãã ããã http://www.snort.org/snort-downloads? â daqãã¼ã¸ã§ã³ daq-0.3 â»ææ°çã¯ä¸è¨URLã§ç¢ºèªãã¦ãã ããã http://www.snort.org/snort-downloads? â GUIãã¼ã« base-1.4.5 adodb511 â å¿ è¦ãªããã±ã¼ã¸ mysql mysql-server mysql-bench mysql-devel htt
snortã®è¨å® /usr/local/snort ã«ã³ãã¼ããsnort.confãã¨ãã£ã¿ã§éããã¾ãã¯ç£è¦ä¸ã«ç½®ããããã¯ã¼ã¯ãã¾ãã¯ãã·ã³ãè¨å®ããã var HOME_NET anyã any ãç£è¦ããããããã¯ã¼ã¯ã«æ¸ãæããã ãã®é¨åã¸ã®è¨è¿°ã¯ãããã¯ã¼ã¯ç°å¢ã 192.168.1.0/255.255.255.0ãä¾ã«æ¸ãã¦ããã ä¾ï¼.192.168.1.0ã®ãããã¯ã¼ã¯ãã¹ã¦ãç£è¦ãããå ´å var HOME_NET 192.168.1.0/24 ä¾ï¼.192.168.1.1ãç£è¦ãããå ´å var HOME_NET 192.168.1.1/32 ä¾ï¼ï¼è¤æ°ã®ãããã¯ã¼ã¯ãè¤æ°ã®ãã·ã³ãç£è¦ãããå ´å ï¼ãããã¯ã¼ã¯ï¼var HOME_NET [192.168.0.0/24,192.168.1.0/24] ï¼ãã·ã³ï¼ãããvar HOME_NET[192.
Snort èµ·åãªãã·ã§ã³ã®è¨å® (/etc/sysconfig/snort) Snort-2.6.x ??ãããsnort ã®èµ·åã¹ã¯ãªãã(/etc/rc.d/init.d/snortd)ã¯ã/etc/sysconfig/snort ãåç §ããããã«å¤æ´ããã¦ãã¾ãã é ä»ããã¦ããéå»ã®ãã¼ã¸ã§ã³ã調ã¹ã¾ãããã以åé å¸ããã¦ããã½ã¼ã¹ã¨ç°ãªãã夿´ããã¦ãã¾ãããã½ã¼ã¹èªä½ã rpm ãæèããå 容ã¨ãªã£ã¦ãã¾ãã ã¢ããã°ã¬ã¼ãã大å¤ãªã®ã§ç°¡åã«ãã¦æ¬²ããã®ã§ããé ä»ããã¦ãã ããã±ã¼ã¸ï¼rpm / src.rpmï¼ ã¯çç¾ãã¦ããæãæ£è¦ãã¾ãã INTERFACE= èµ·åå æ°ã«é¢ãã¦ã¯ã/etc/sysconfig/snort ã§æå®ãã¾ãã /etc/sysconfig/snort ã§æå®å¯è½ãªèµ·åãªãã·ã§ã³ã¯ä»¥ä¸ã®éãã§ãã
ï¼ï¼ã¯ããã« ä¼ç¤¾ã®è·åã§ç¤¾å ããã®æ å ±æµåºãé²ãçºã«IDS/IPSã®å°å ¥ãæ¤è¨ãã¦ããã One Point Firewallãããã®ãå°å ¥ãããã¨ãã¦ããã®ã ãããããã調ã¹ã¦ããã IDSã¨ãã¦FreeBSDã§ãsnortã使ç¨ããäºã«ããå¯è½ã§ããäºãåãã£ãã ãéããããã®ã§ããã®åã人件費ã«èãã¦è©¦ãã«ã¤ã³ã¹ãã¼ã«ãã¦åããã¾ããã ããã¦ããã¾ãããæ£å¼ç¨¼åã¸ã¨é²ãã¦ããæã§ãã èªå® ãµã¼ãã¼ã®æ²ç¤ºæ¿ã«å®£ä¼åºåã®æ¸ãè¾¼ã¿ããããã®ã§ããããå©ç¨ã㦠æé¤ã§ããªãããã©ã¤ãã¦è¦ãçºã«å°å ¥ãã¦è¦ãã ãããã«ã¼ã«ã䏿ãä½ããªãã®ã§ãæ¬æ¥ã®ç¨éã§ãã䏿£ä¾µå ¥ã¨ããæå³ã§ ã¤ã³ã¹ãã¼ã«ã稼åãã¦è¦ãäºã«ããã æè¿ã§ã¯ã´ãã¡ã¼ã«ãå¤ããæ²ç¤ºæ¿ãéªéãªã¢ã¯ã»ã¹ãããããã¨ã¶ã£ãããªã®ã§ çãããããã¦ã¿ã¦ã¯ãããã§ããããï¼ ï¼ï¼ã¤ã³ã¹ãã¼ã« ã¾ããsnortæ¬ä½ãã¤ã³ã¹ãã¼ã«ãã¾
â snortã®èµ·åãã§ã㯠$ sudo /etc/init.d/snort status Status of snort daemon(s): eth0 OK. â å ¨ä½ã®ãã£ã«ã¿ã«ã¼ã«ãã§ãã¯(local.rulesã追å ãã«ã¼ã«å ¨ä½ãæ´æ°ããæãªã©) ã-Tãã¯ãã¹ããªãã·ã§ã³ãã-n1ãã¯1ãã±ãããåä¿¡ãããçµäºããã $ sudo snort -T -c /etc/snort/snort.conf 2>&1 | grep -i "warn\|error\|exit" ERROR: /etc/snort/rules/bad-traffic.rules(27): Couldnt resolve hostname DEBIAN_SNORT_HOME_NET Fatal Error, Quitting.. â DEBIAN_SNORT_HOME_NETãåå ã®æ§åãªã®ã§ãä¿®æ£ã $ sud
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}