Re: Ryu Controller
"Dr. Mostafa Abdallah. Ammar" <[email protected]> Tue, 26 Nov 2019 08:36:26 +0000
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <[email protected]> |
Hi, I made a similar research on how to integrate BRO and snort IDS with SDN controller Best Regards, Mostafa Abdallah Ammar, PhD. Head of Information Security Department CCIE security #23971 Arab Academy For Science And Technology & maritime Transport Computer Networks & Data Center (CNDC) Mobile: 002 01001983674 ________________________________________ From: [email protected] <[email protected]> on behalf of Johanna Amann <[email protected]> Sent: Tuesday, November 26, 2019 7:45 AM To: Priyatham Ganta Cc: [email protected] Subject: Re: [Zeek] Ryu Controller Hi, > I want to integrate Ryu controller with Zeek IDS for a project and I > need > help to do this. Can anyone help me with it? if you just want send commands to Ryu from Zeek - use the netcontrol framework. There actually is a Ryu plugin for it, although that might have bitrotted a bit by now (so I won’t guarantee that it just works out of the box anymore). In any case - it might be worth taking a look at the netcontrol documentation that highlights how netcontrol operates: https://docs.zeek.org/en/stable/frameworks/netcontrol.html It also shows how to instantiate everything. To make things a bit complicated, there are two ways to interface with Ryu. The first one uses the Ryu REST API directly from Zeek. This does not scale very well - but is pretty simple and should still work unless they changed the API. That plugin ships with Zeek and is at https://github.com/zeek/zeek/blob/master/scripts/base/frameworks/openflow/plugins/ryu.zeek. The second way is to use the generic broker plugin on the Zeek side - and write a Ryu controller that can interact with that. A Ryu controller implementing this is in the zeek-netcontrol repository (which is contained in aux if you download the distribution). https://github.com/zeek/zeek-netcontrol/tree/master/openflow contains the source code as well as an example script that ties everything together. I hope this helps a bit to get started :) Johanna _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek