Re: BB, SNMP, security

Jeff Stoner <[email protected]> 17 Feb 2004 10:00:20 -0500
Newsgroups gmane.network.bb4.devel
Organization Blackboard, Inc.
Message-ID <[email protected]>
On Tue, 2004-02-17 at 02:26, Mouton Blanc wrote:
> I am using BB to monitor some honeypots as part of my
> intrusion detection system. However, O'Reilly's
> "Practical Unix & Internet Security" does not
> recommend using SNMP as part of an intrusion detection
> system or any security infrastructure system.
> So I am wondering what the potential security issues
> are regarding using BB and the use of SNMP, snmptrap
> in particular.
> 
> I think one of the issue could be that by using
> snmptrap, the intruder would be able to figure out the
> BB server which I want to keep hidden in my case. Does
> my problem make sense? I hope I am not
> misunderstanding how BB works.

Big Brother is not an SNMP-based monitoring tool. It does have limited
SNMP capabilities. Big Brother uses its own proprietary text-based
communications protocol between the client and the server.

Actually, it wouldn't matter if you used SNMP, the snmptrap integration
script for Big Brother or just Big Brother itself - they all report back
to the Big Brother server. You could:

* hack the kernel/libraries/binaries yourself to hide the monitoring
process(es), network connection(s) and possibly directories/files so
intruders to your honeypot won't find them

* use bb-fetch from deadcat.net to do a server-pull - which has its own
implications for security

* something else I can't think of right now but is really clever and
worth billions of dollars in the hands of the right marketing and sales
people

BTW, I am not a security expert. Books are not security experts. A
security expert is someone who knows "it's not a matter of 'if' but a
matter of 'when'" and who can put the proper policies, procedures and
equipment/resources in place.

-- 
--Jeff
Blackboard Operations & Support

This email may contain privileged and confidential information. It is
intended only for the use of the adressee(s). I'll further add that if
this message is not digitally signed or encrypted using one of my keys,
than I can deny composing it in the first place.
--
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-=
To unsubscribe from this list send e-mail to mailto:[email protected]
with unsubscribe bbd in the BODY of the message.