Re: [Prelude Hybrid IDS] #245: New LML-Ruleset for Kojoney SSH Honeypot - please review

"Prelude Hybrid IDS" <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#245: New LML-Ruleset for Kojoney SSH Honeypot - please review
-------------------------+--------------------------------------------------
 Reporter:  bjou         |        Owner:  yoann
     Type:  defect       |       Status:  new  
 Priority:  normal       |    Milestone:       
Component:  prelude-lml  |      Version:  0.9  
 Severity:  trivial      |   Resolution:       
 Keywords:               |  
-------------------------+--------------------------------------------------
Comment (by yoann):

 Thanks for this contribution!

 Here are a few comments concerning the ruleset. Once the following issues
 are discussed and/or fixed, we will be able to include this ruleset within
 the LML distribution.


  * In case the software might report Ipv6 attack, it would be best to
 match the IP address using (\S+), and leaving address.category unspecified
 (Prelude-Manager Normalizer will take care of setting it appropriately).

  * Instead of setting the login within AdditionalData, did you investigate
 whether setting it within target User/UserID (with category set to ''os-
 device'') would be appropriate?

  * ''commandline'' should probably be spelled ''command line''

  * ''(executing .*|COMMAND .*)'': The command is an interesting
 information that should be captured and assigned within an IDMEF field.
 Additionally, in case where ''executing'' is matched, you might want to
 set the target.process entry with the name of the process (and the path,
 if you are able to retrieve it).

  * ''Saved the file .*'': No need for the wildcard here, you can just use:
   ''\[SSHChannel session \(\d+\) on SSHService ssh-connection on
 SSHServerTransport,\d+,([\d\.]+)\] Saved the file''

  * Additionally, is there any reason you don't assign the saved filename
 information within the IDMEF message?

  * In all Kojoney log messages, what does the number following
 ''SSHServerTransport'' correspond to (example:
 SSHServerTransport,'''3''')?

 Hope this help,

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/245#comment:1>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.