This small page intend to present mechanisms used to create a running and interesting solution on a Linux platform.
A conference has been made at Solutions Linux 2006 on this theme
Overview
We wanted to create an IPS (Intrusion Prevention Solution) solution able to protect assets by detecting vulnerabilities on the network and stopping threats when it matches this vulnerability. Nevertheless, one knows production environment are often reluctant in dropping business traffic. That's why we used a second level, a monitoring level used to warn IT team when a threat signature is being observed in accepted businness packets.
Download
Configuration files package (tar.gz) : snort_nessus.tar.gz
Movie detailing the main project usage : ips.avi
Presentation file for Linux Solutions 2006 in Paris : Solution Linux 2006 Correlation et IPS.pdf
Used components
snort- inline , oinkmaster , crafted shell scripts
nessus , crafted shell scripts
prelude , prelude-lml , prewikka , crafted shell scripts
iptables
Graphes


Technical details
Some files used have to be explained :
To do now
Many changes could be done:
Prelude developpers are working hard in having SEC (Simple Event Correlation) rulebase correlation engine integrated directly within Prelude-Manager. This new features will probably open SIM market to Prelude.
Credit
Alexis Caurette - David Bizeul
alexis dot caurette at gmail dot com
- dbizeul at gmail dot com