Re: Ryu Controller
Priyatham Ganta <[email protected]> Tue, 26 Nov 2019 15:59:47 -0800
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CABXPuZ_ieFcu=YOzoNcQGsHMeez8kZrCu7J50rvHCssjQWmd5Q@mail.gmail.com> |
--===============1455419719== Content-Type: multipart/alternative; boundary="0000000000006b1059059848adb1" --0000000000006b1059059848adb1 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi, Yes, it is for a school project and would like to use Bro as IDS. And I would like Bro to generate active alerts for the incoming traffic. How can I do it? Thanks On Tue, 26 Nov 2019 at 14:20, Richard Bejtlich <[email protected]> wrote: > Why are you interested in this approach? Is it a school project? > > Zeek isn=E2=80=99t designed to be an intrusion detection system that crea= tes > alerts, although it does produce notices. You might be better off with > Suricata if you want alerts. > > Sincerely, > > Richard > > On Tue, Nov 26, 2019 at 4:17 PM Priyatham Ganta <[email protected]> > wrote: > >> Hi, >> >> I'm trying to run Bro as IDS. Hence, I don't want to show all the logs o= n >> the console.I just want to look at the alerts generated by Bro if there = are >> any attacks on the network. That's the reason I want to print only the >> alerts and not logs. >> How do I run Bro in IDS mode? >> >> For Bro to run as IDS, there should be some policies configured with >> which this application will differentiate between normal traffic and >> malicious traffic. I want to look at those policies. >> >> Can you help me with this? >> >> Thanks >> >> On Tue, 26 Nov 2019 at 10:54, Johanna Amann <[email protected]> wrote: >> >>> Hi, >>> >>> > How can I run bro for the current traffic and show the alerts on a >>> > console >>> > instead of logs? >>> >>> you can run it on the command line without using zeekctl/broctl using >>> zeek (or bro) -i [interfacename]. However, logs will always written to >>> files - it does not really make sense to write them to the console, >>> which would make it hard to distinguish between the different log >>> streams. >>> >>> Note - most Zeek logs are policy neutral and not really alerts=E2=80=A6 >>> >>> > Also where can I check the policies that are configured to Bro for >>> > IDS? >>> >>> I don=E2=80=99t 100% get the questions. If you load misc/loaded-scripts= in >>> your configuration, you will get a loaded-scripts.log which will show >>> you all script files that are loaded. The default configuration of Zeek >>> loads most protocol analyzers and writes their log-files. >>> >>> > Also what is the difference between the broctl binary and bro binary? >>> >>> zeekctl/broctl is the management application to start zeek cluster >>> setups. See e.g. https://github.com/zeek/zeekctl - or >>> https://docs.zeek.org/en/stable/quickstart/ for a getting started guide >>> that mentions this. >>> >>> Johanna >>> >> _______________________________________________ >> Zeek mailing list >> [email protected] >> http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek > > -- > Richard Bejtlich > Principal Security Strategist, Corelight > https://corelight.blog/author/richardbejtlich/ > --0000000000006b1059059848adb1 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Hi,<div><br></div><div>Yes, it is for a school project and= would like to use Bro as IDS. And I would like Bro to generate active aler= ts for the incoming traffic. How can I do it?</div><div><br></div><div>Than= ks</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmai= l_attr">On Tue, 26 Nov 2019 at 14:20, Richard Bejtlich <<a href=3D"mailt= o:[email protected]">[email protected]</a>> wrote:<br></div><blo= ckquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left= :1px solid rgb(204,204,204);padding-left:1ex"><div><div dir=3D"auto">Why ar= e you interested in this approach? Is it a school project?=C2=A0</div><div = dir=3D"auto"><br></div><div dir=3D"auto">Zeek isn=E2=80=99t designed to be = an intrusion detection system that creates alerts, although it does produce= notices. You might be better off with Suricata if you want alerts.</div></= div><div dir=3D"auto"><br></div><div dir=3D"auto">Sincerely,</div><div dir= =3D"auto"><br></div><div dir=3D"auto">Richard=C2=A0</div><div><br><div clas= s=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Nov 26, 201= 9 at 4:17 PM Priyatham Ganta <<a href=3D"mailto:[email protected]"= target=3D"_blank">[email protected]</a>> wrote:<br></div><blockqu= ote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px= solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr">Hi,<div><br><div= >I'm trying to run Bro as IDS. Hence, I don't want to show all the = logs on the console.I just want to look at the alerts generated by Bro if t= here are any attacks on the network. That's the reason I want to print = only the alerts and not logs.</div><div>How do I run Bro in IDS mode?</div>= <div><br></div><div>For Bro to run as IDS, there should be some policies co= nfigured with which this application will differentiate between normal traf= fic and malicious traffic. I want to look at those policies.</div></div><di= v><br></div><div>Can you help me with this?</div><div><br></div><div>Thanks= </div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_= attr">On Tue, 26 Nov 2019 at 10:54, Johanna Amann <<a href=3D"mailto:joh= [email protected]" target=3D"_blank">[email protected]</a>> wrote:<br></div><= blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-l= eft:1px solid rgb(204,204,204);padding-left:1ex">Hi,<br> <br> > How can I run bro for the current traffic and show the alerts on a <br= > > console<br> > instead of logs?<br> <br> you can run it on the command line without using zeekctl/broctl using <br> zeek (or bro) -i [interfacename]. However, logs will always written to <br> files - it does not really make sense to write them to the console, <br> which would make it hard to distinguish between the different log <br> streams.<br> <br> Note - most Zeek logs are policy neutral and not really alerts=E2=80=A6<br> <br> > Also where can I check the policies that are configured to Bro for <br= > > IDS?<br> <br> I don=E2=80=99t 100% get the questions. If you load misc/loaded-scripts in = <br> your configuration, you will get a loaded-scripts.log which will show <br> you all script files that are loaded. The default configuration of Zeek <br= > loads most protocol analyzers and writes their log-files.<br> <br> > Also what is the difference between the broctl binary and bro binary?<= br> <br> zeekctl/broctl is the management application to start zeek cluster <br> setups. See e.g. <a href=3D"https://github.com/zeek/zeekctl" rel=3D"norefer= rer" target=3D"_blank">https://github.com/zeek/zeekctl</a> - or <br> <a href=3D"https://docs.zeek.org/en/stable/quickstart/" rel=3D"noreferrer" = target=3D"_blank">https://docs.zeek.org/en/stable/quickstart/</a> for a get= ting started guide <br> that mentions this.<br> <br> Johanna<br> </blockquote></div> _______________________________________________<br> Zeek mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><br> <a href=3D"http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek" rel=3D"n= oreferrer" target=3D"_blank">http://mailman.ICSI.Berkeley.EDU/mailman/listi= nfo/zeek</a></blockquote></div></div>-- <br><div dir=3D"ltr"><div dir=3D"lt= r"><div><div dir=3D"ltr"><div><div dir=3D"ltr">Richard Bejtlich<div>Princip= al Security Strategist, Corelight</div><div><a href=3D"https://corelight.bl= og/author/richardbejtlich/" target=3D"_blank">https://corelight.blog/author= /richardbejtlich/</a><br></div></div></div></div></div></div></div> </blockquote></div> --0000000000006b1059059848adb1-- --===============1455419719== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek --===============1455419719==--