Prelude and Sguil capabilities
Robin Gruyters <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi ya,
The last few weeks I've been playing with Sguil[1] and I must admit they
have done some nice things with it:
- "realtime" events;
- analyze session data;
- parse raw tcpdump files (for packets matching the req. sessions or save
raw data for further analyze (ethereal))
Altough it has these features that Prelude doesn't have (except for saving
session data, thanks to Frank van Vliet), it doesn't confince me to use it.
What I dislike about it is:
- the use of the GUI;
You have to install different packages (tcl/tk) to view the data.
Also with all the little/narrow windows/panels, you can't really see the
overall alerts.
And thoses annoying errors/warnings from tcl/tk.
- You have to connect to each sensor separately to view the alerts from each
sensor;
The problem with this is, you don't see the overall view of the alerts. So
if an intruder found and exploit on one of your servers, how far did the
intruder got through your network.
To do this with Sguil, you have to connect to each sensor separatly, and
that to me is a big disadvantage.
What I want to do is try to implement some features from Sguil in
Prelude/Prewikka:
- semi-realtime events; (by using Javascripting)
- Save full packets in tcpdump format; (which we already have
up-and-running)
- Add more external command; (p0f, tcpdump, etc)
- and add possibility to extract/export raw data (tcpdump data) from a
session for further analysis.
If other people have more ideas or suggestions, just let us know.
[1] - Sguil: http://sguil.sourceforge.net
Regards,
--
Robin Gruyters
Network and Security Engineer
Yirdis B.V.
I: http://yirdis.com
P: +31 (0)36 5300394
F: +31 (0)36 5489119
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel