Re: Ryu Controller

Priyatham Ganta <[email protected]> Tue, 26 Nov 2019 15:59:47 -0800
Newsgroups gmane.comp.security.detection.bro
Message-ID <CABXPuZ_ieFcu=YOzoNcQGsHMeez8kZrCu7J50rvHCssjQWmd5Q@mail.gmail.com>
--===============1455419719==
Content-Type: multipart/alternative; boundary="0000000000006b1059059848adb1"

--0000000000006b1059059848adb1
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi,

Yes, it is for a school project and would like to use Bro as IDS. And I
would like Bro to generate active alerts for the incoming traffic. How can
I do it?

Thanks

On Tue, 26 Nov 2019 at 14:20, Richard Bejtlich <[email protected]>
wrote:

> Why are you interested in this approach? Is it a school project?
>
> Zeek isn=E2=80=99t designed to be an intrusion detection system that crea=
tes
> alerts, although it does produce notices. You might be better off with
> Suricata if you want alerts.
>
> Sincerely,
>
> Richard
>
> On Tue, Nov 26, 2019 at 4:17 PM Priyatham Ganta <[email protected]>
> wrote:
>
>> Hi,
>>
>> I'm trying to run Bro as IDS. Hence, I don't want to show all the logs o=
n
>> the console.I just want to look at the alerts generated by Bro if there =
are
>> any attacks on the network. That's the reason I want to print only the
>> alerts and not logs.
>> How do I run Bro in IDS mode?
>>
>> For Bro to run as IDS, there should be some policies configured with
>> which this application will differentiate between normal traffic and
>> malicious traffic. I want to look at those policies.
>>
>> Can you help me with this?
>>
>> Thanks
>>
>> On Tue, 26 Nov 2019 at 10:54, Johanna Amann <[email protected]> wrote:
>>
>>> Hi,
>>>
>>> > How can I run bro for the current traffic and show the alerts on a
>>> > console
>>> > instead of logs?
>>>
>>> you can run it on the command line without using zeekctl/broctl using
>>> zeek (or bro) -i [interfacename]. However, logs will always written to
>>> files - it does not really make sense to write them to the console,
>>> which would make it hard to distinguish between the different log
>>> streams.
>>>
>>> Note - most Zeek logs are policy neutral and not really alerts=E2=80=A6
>>>
>>> > Also where can I check the policies that are configured to Bro for
>>> > IDS?
>>>
>>> I don=E2=80=99t 100% get the questions. If you load misc/loaded-scripts=
 in
>>> your configuration, you will get a loaded-scripts.log which will show
>>> you all script files that are loaded. The default configuration of Zeek
>>> loads most protocol analyzers and writes their log-files.
>>>
>>> > Also what is the difference between the broctl binary and bro binary?
>>>
>>> zeekctl/broctl is the management application to start zeek cluster
>>> setups. See e.g. https://github.com/zeek/zeekctl - or
>>> https://docs.zeek.org/en/stable/quickstart/ for a getting started guide
>>> that mentions this.
>>>
>>> Johanna
>>>
>> _______________________________________________
>> Zeek mailing list
>> [email protected]
>> http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
>
> --
> Richard Bejtlich
> Principal Security Strategist, Corelight
> https://corelight.blog/author/richardbejtlich/
>

--0000000000006b1059059848adb1
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi,<div><br></div><div>Yes, it is for a school project and=
 would like to use Bro as IDS. And I would like Bro to generate active aler=
ts for the incoming traffic. How can I do it?</div><div><br></div><div>Than=
ks</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmai=
l_attr">On Tue, 26 Nov 2019 at 14:20, Richard Bejtlich &lt;<a href=3D"mailt=
o:[email protected]">[email protected]</a>&gt; wrote:<br></div><blo=
ckquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left=
:1px solid rgb(204,204,204);padding-left:1ex"><div><div dir=3D"auto">Why ar=
e you interested in this approach? Is it a school project?=C2=A0</div><div =
dir=3D"auto"><br></div><div dir=3D"auto">Zeek isn=E2=80=99t designed to be =
an intrusion detection system that creates alerts, although it does produce=
 notices. You might be better off with Suricata if you want alerts.</div></=
div><div dir=3D"auto"><br></div><div dir=3D"auto">Sincerely,</div><div dir=
=3D"auto"><br></div><div dir=3D"auto">Richard=C2=A0</div><div><br><div clas=
s=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Nov 26, 201=
9 at 4:17 PM Priyatham Ganta &lt;<a href=3D"mailto:[email protected]"=
 target=3D"_blank">[email protected]</a>&gt; wrote:<br></div><blockqu=
ote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px=
 solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr">Hi,<div><br><div=
>I&#39;m trying to run Bro as IDS. Hence, I don&#39;t want to show all the =
logs on the console.I just want to look at the alerts generated by Bro if t=
here are any attacks on the network. That&#39;s the reason I want to print =
only the alerts and not logs.</div><div>How do I run Bro in IDS mode?</div>=
<div><br></div><div>For Bro to run as IDS, there should be some policies co=
nfigured with which this application will differentiate between normal traf=
fic and malicious traffic. I want to look at those policies.</div></div><di=
v><br></div><div>Can you help me with this?</div><div><br></div><div>Thanks=
</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_=
attr">On Tue, 26 Nov 2019 at 10:54, Johanna Amann &lt;<a href=3D"mailto:joh=
[email protected]" target=3D"_blank">[email protected]</a>&gt; wrote:<br></div><=
blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-l=
eft:1px solid rgb(204,204,204);padding-left:1ex">Hi,<br>
<br>
&gt; How can I run bro for the current traffic and show the alerts on a <br=
>
&gt; console<br>
&gt; instead of logs?<br>
<br>
you can run it on the command line without using zeekctl/broctl using <br>
zeek (or bro) -i [interfacename]. However, logs will always written to <br>
files - it does not really make sense to write them to the console, <br>
which would make it hard to distinguish between the different log <br>
streams.<br>
<br>
Note - most Zeek logs are policy neutral and not really alerts=E2=80=A6<br>
<br>
&gt; Also where can I check the policies that are configured to Bro for <br=
>
&gt; IDS?<br>
<br>
I don=E2=80=99t 100% get the questions. If you load misc/loaded-scripts in =
<br>
your configuration, you will get a loaded-scripts.log which will show <br>
you all script files that are loaded. The default configuration of Zeek <br=
>
loads most protocol analyzers and writes their log-files.<br>
<br>
&gt; Also what is the difference between the broctl binary and bro binary?<=
br>
<br>
zeekctl/broctl is the management application to start zeek cluster <br>
setups. See e.g. <a href=3D"https://github.com/zeek/zeekctl" rel=3D"norefer=
rer" target=3D"_blank">https://github.com/zeek/zeekctl</a> - or <br>
<a href=3D"https://docs.zeek.org/en/stable/quickstart/" rel=3D"noreferrer" =
target=3D"_blank">https://docs.zeek.org/en/stable/quickstart/</a> for a get=
ting started guide <br>
that mentions this.<br>
<br>
Johanna<br>
</blockquote></div>
_______________________________________________<br>
Zeek mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><br>
<a href=3D"http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek" rel=3D"n=
oreferrer" target=3D"_blank">http://mailman.ICSI.Berkeley.EDU/mailman/listi=
nfo/zeek</a></blockquote></div></div>-- <br><div dir=3D"ltr"><div dir=3D"lt=
r"><div><div dir=3D"ltr"><div><div dir=3D"ltr">Richard Bejtlich<div>Princip=
al Security Strategist, Corelight</div><div><a href=3D"https://corelight.bl=
og/author/richardbejtlich/" target=3D"_blank">https://corelight.blog/author=
/richardbejtlich/</a><br></div></div></div></div></div></div></div>
</blockquote></div>

--0000000000006b1059059848adb1--

--===============1455419719==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
--===============1455419719==--