Re: prelude-correlator
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1164025728.1647.10.camel@arwen> |
Hi Bjoern, On Wed, 2006-11-08 at 00:25 +0100, Bjoern Weiland wrote: > Hey guys, > > as I have been told, the SEC correlation is deprecated, > prelude-correlator is the new state of the art. As I have none of it > used yet, I do have some questions about it. > > I currently have nepenthes report into prelude and make it viewable via > prewikka. Problem is, that nepenthes listens to about 200 IP addresses, > so there is a new event raised every few minutes or so which spams my > prewikka. Most of the time, there are worms that come from one IP and > hit several nepenthes IPs, i.e. one source and several destinations. Maybe Nepenthes itself could be modified so that one alert carry multiple target address rather than one target per alert? > Every event has a prewikka entry though, which is not very clearly arranged. > I'd love to have these entries correlated, i.e. one prewikka entry for > every *source* IP (regardless of its destination) This can be done from Prewikka by disabling target host aggregation (click on the "Target" top table header, remove the "Group entry by target" entry). > Question is, if that is possible with a ruleset for prelude-correlator. > Is the correlator designed for exactly this purpose or (if not) what > else can I use it for then... You can use Prelude-Correlator to catch the original Nepenthes events, and to construct a Correlation alert carrying all the target carried by the different alerts. Regards, -- Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies Tel: +33 (0)8 70 70 21 58 Fax: +33(0)4 78 42 21 58 http://www.prelude-ids.com _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel