Re: [Prelude Hybrid IDS] #245: New LML-Ruleset for Kojoney SSH Honeypot - please review
"Prelude Hybrid IDS" <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#245: New LML-Ruleset for Kojoney SSH Honeypot - please review
-------------------------+--------------------------------------------------
Reporter: bjou | Owner: yoann
Type: defect | Status: new
Priority: normal | Milestone:
Component: prelude-lml | Version: 0.9
Severity: trivial | Resolution:
Keywords: |
-------------------------+--------------------------------------------------
Comment (by yoann):
Thanks for this contribution!
Here are a few comments concerning the ruleset. Once the following issues
are discussed and/or fixed, we will be able to include this ruleset within
the LML distribution.
* In case the software might report Ipv6 attack, it would be best to
match the IP address using (\S+), and leaving address.category unspecified
(Prelude-Manager Normalizer will take care of setting it appropriately).
* Instead of setting the login within AdditionalData, did you investigate
whether setting it within target User/UserID (with category set to ''os-
device'') would be appropriate?
* ''commandline'' should probably be spelled ''command line''
* ''(executing .*|COMMAND .*)'': The command is an interesting
information that should be captured and assigned within an IDMEF field.
Additionally, in case where ''executing'' is matched, you might want to
set the target.process entry with the name of the process (and the path,
if you are able to retrieve it).
* ''Saved the file .*'': No need for the wildcard here, you can just use:
''\[SSHChannel session \(\d+\) on SSHService ssh-connection on
SSHServerTransport,\d+,([\d\.]+)\] Saved the file''
* Additionally, is there any reason you don't assign the saved filename
information within the IDMEF message?
* In all Kojoney log messages, what does the number following
''SSHServerTransport'' correspond to (example:
SSHServerTransport,'''3''')?
Hope this help,
--
Ticket URL: <https://trac.prelude-ids.org/ticket/245#comment:1>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel