Ãâ·Ñ×¢²á ²é¿´ÐÂÌû |

Chinaunix

  ƽ̨ ÂÛ̳ ²©¿Í ÎÄ¿â
×î½ü·ÃÎÊ°å¿é ·¢ÐÂÌû
Â¥Ö÷: phiazat
´òÓ¡ ÉÏÒ»Ö÷Ìâ ÏÂÒ»Ö÷Ìâ

»ùÓÚSnortµÄÈëÇÖ¼ì²âϵͳ [¸´ÖÆÁ´½Ó]

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
81Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:41 |ÏÔʾȫ²¿Â¥²ã
ÏÖÔÚÒªÅäÖÃACIDʹ֮Äܹ»ÓëMySQLÊý¾Ý¿â½»»¥£¬²¢Ê¹SnortÄܹ»Ê¹ÓÃPHPLOTÈí¼þ°ü¡£ÎÒÃÇÐèÒªÐÞ¸ÄÅäÖÃÎļþacid_conf.phpÖеÄһЩ²ÎÊý£¬Õâ¸öÎļþÔÚÄãÊÍ·ÅACIDÎļþµÄĿ¼£¬ÄãÐèÒª×öÒÔÏÂÉèÖãº\r\nADODBÎļþµÄλÖÃÔÚÕâÀïÊÇ./adodb£¬Äã¿ÉÒÔ¸ù¾Ý×Ô¼ºµÄÇé¿öÐ޸ġ£\r\nÊý¾Ý¿â·þÎñÆ÷µÄÀàÐÍ£¬ÔÚÕâÀïÊÇmysql¡£\r\nMySQL¼Ç¼SnortÊý¾ÝµÄÊý¾Ý¿âÃû¡£\r\nMySQLÊý¾Ý¿â·þÎñÆ÷Ãû³Æ»òÕßIPµØÖ·¡£\r\nMySQLÊý¾Ý¿âÓû§ÃûºÍ¿ÚÁî¡£\r\n±¸·ÝÊý¾Ý¿âµÄÃû³Æ£¬Èç¹ûÄ㱸·ÝÊý¾ÝµÄ»°¡£\r\n±¸·ÝÊý¾Ý¿âµÄ·þÎñÆ÷Ö÷»úÃû»òÕßIPµØÖ·£¬ÔÚÕâÀÊÇÓësnortÊý¾Ý¿âÏàͬµÄ£¬¶¼ÊÇlocalhost¡£\r\nPHPLOTÎļþµÄλÖã¬ÔÚÕâÀïÊÇ./phplot-4.4.6¡£\r\nÕâЩÐÅÏ¢ÔÚacid_conf.phpÎļþµÄ¿ªÊ¼²¿·Ö£¬ÏÂÃæÊÇÒ»¸öʵÀý£º\r\n<?php\r\n$ACID_VERSION = \"0.9.6b21\";\r\n/* Path to the DB abstraction library\r\n* (Note: DO NOT include a trailing backslash after the\r\n* directory)\r\n* e.g. $foo = \"/tmp\" [OK]\r\n* $foo = \"/tmp/\" [OK]\r\n* $foo = \"c:\\tmp\" [OK]\r\n* $foo = \"c:\\tmp\\\" [WRONG]\r\n*/\r\n$DBlib_path = \"./adodb\";\r\n/* The type of underlying alert database\r\n*\r\n* MySQL : \"mysql\"\r\n* PostgresSQL : \"postgres\"\r\n* MS SQL Server : \"mssql\"\r\n*/\r\n$DBtype = \"mysql\";\r\n/* Alert DB connection parameters\r\n* - $alert_dbname : MySQL database name of Snort\r\n: alert DB\r\n* - $alert_host : host on which the DB is stored\r\n* - $alert_port : port on which to access the DB\r\n* - $alert_user : login to the database with\r\n: this user\r\n* - $alert_password : password of the DB user

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
82Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:41 |ÏÔʾȫ²¿Â¥²ã
* This information can be gleaned from the Snort database\r\n* output plugin configuration.\r\n*/\r\n$alert_dbname = \"snort\";\r\n$alert_host = \"localhost\";\r\n$alert_port = \"\";\r\n$alert_user = \"rr\";\r\n$alert_password = \"rr78x\";\r\n/* Archive DB connection parameters */\r\n$archive_dbname = \"snort_archive\";\r\n$archive_host = \"localhost\";\r\n$archive_port = \"\";\r\n$archive_user = \"rr\";\r\n$archive_password = \"rr78x\";\r\n/* Type of DB connection to use\r\n* 1 : use a persistant connection (pconnect)\r\n* 2 : use a normal connection (connect)\r\n*/\r\n$db_connect_method = 1;\r\n/* Path to the graphing library\r\n* (Note: DO NOT include a trailing backslash after the\r\ndirectory)\r\n*/\r\n$ChartLib_path = \"./phplot-4.4.6\";\r\nÔÚÕâÀÎÒÃÇÉèÖõÄÓû§Ãû¡¢¿ÚÁîºÍÊý¾Ý¿âÃûºÍÔÚsnort.confÖÐÊÇÏàͬµÄ£¬ÏÂÃæÊǶÔÅäÖÃÎļþµÄ½âÊÍ£º\r\nÏÂÃæµÄÒ»ÐÐÓÃÀ´ÉèÖÃADODBÎļþµÄ·¾¶£º\r\n$DBlib_path = \"./adodb\";\r\nÏÂÃæµÄÒ»ÐÐÓÃÀ´ÉèÖÃÊý¾Ý¿âµÄÀàÐÍ£º\r\n$DBtype = \"mysql\";\r\nÏÂÃæµÄ¼¸ÐÐÓÃÀ´ÉèÖÃSnortµÄÖ÷Êý¾Ý¿âÐÅÏ¢£º\r\n$alert_dbname = \"snort\";\r\n$alert_host = \"localhost\";\r\n$alert_port = \"\";\r\n$alert_user = \"rr\";\r\n$alert_password = \"rr78x\";\r\nÏÂÃæµÄ¼¸ÐÐÓÃÀ´ÉèÖÃSnort±¸·ÝÊý¾Ý¿âÐÅÏ¢£º\r\n$alert_dbname = \"snort_archive\";\r\n$alert_host = \"localhost\";\r\n$alert_port = \"\";\r\n$alert_user = \"rr\";\r\n$alert_password = \"rr78x\";\r\nÏÂÃæµÄÒ»ÐÐÓÃÀ´ÕâÊÇPHPLOTÎļþµÄ·¾¶£º\r\n$ChartLib_path = \"./phplot-4.4.6\";\r\nÅäÖÃÍê³Éºó£¬Äã¾Í¿ÉÒÔÓÃweb½çÃæ·ÃÎÊACIDÁË¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
83Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |ÏÔʾȫ²¿Â¥²ã
6£®3ʹÓÃACID\r\nÍê³ÉÇ°ÃæµÄ¹¤×÷ºó£¬Äã¿ÉÒÔÓÃURLÀ´·ÃÎÊACIDÁË£º http://<ÄãµÄweb·þÎñÆ÷>/acid/¡£ÀýÈ磬ÎÒµÄweb·þÎñÆ÷µÄµØÖ·ÊÇ192.168.1.2,Òò´Ë£¬ÎÒ¾ÍÓÃhttp://192.168.1.2/acid/¡£\r\nµÚÒ»´Î·ÃÎʵÄʱºò£¬Ä㻹ÐèҪͨ¹ýweb½çÃæ×öһЩÉèÖã¬Èçͼ6-1Ëùʾ¡£\r\nÔÚÕâ¸ö´°¿Ú£¬µã»÷SetupÒ³ÃæÁ¬½Ó£¬Ò³Ãæ¾Í»áתµ½DBÉèÖÃÒ³Ã棬Èçͼ6-2Ëùʾ¡£\r\nÔÚÕâ¸öÒ³Ã棬µã»÷¡°Create ACID AG¡±Á¬½Ó£¬ACID¾Í»áÔÚsnortÊý¾Ý¿âÖд´½¨Ò»Ð©×Ô¼ºËùÐèÒªµÄ±í£¬ÒÔÖ§³ÖSnort¡£Í¼6-3ÏÔʾÁË´´½¨Ð±íµÄ½á¹û¡£\r\n        ÔÚͼ6-3ËùʾµÄÒ³Ã棬Äã¿ÉÒÔµã»÷¡°Main Page¡±µ½Ö÷Ò³Ãæ¡£\r\n6-1£¬6-2£¬6-3Ò³ÃæÔÚÄãÏÂÒ»´ÎʹÓÃACIDµÄʱºò¾Í²»»á³öÏÖÁË¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
84Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |ÏÔʾȫ²¿Â¥²ã
6.3.1ACIDÖ÷Ò³Ãæ\r\nACIDÖ÷Ò³ÃæÏÔʾµ±Ç°Êý¾ÝµÄ¸ÅÒª¡£ËüÓò»Í¬µÄ²¿·Ö·Ö×éÏÔʾÐÅÏ¢¡£Äã¿ÉÒÔ¿´µ½¸÷¸öЭÒéµÄÁ÷Á¿¸Å¿ö£¬È¡µÃij¸öSnort¸ÐÓ¦Æ÷µÄ¿ìÕÕÐÅÏ¢£¬ËÑË÷Êý¾ÝµÈµÈ£¬Èçͼ6-4Ëùʾ¡£\r\n\r\nµã»÷ͼ6-4ÉÏÃæµÄÁ¬½Ó£¬Äã¿ÉÒÔ¿´µ½´óÁ¿µÄÐÅÏ¢¡£\r\n\r\nÏòÊý¾Ý¿â¼Ç¼Êý¾ÝµÄ̽²âÆ÷ÁÐ±í¡£\r\n¸æ¾¯µÄÊýÁ¿¼°ÏêϸÐÅÏ¢¡£\r\nËù²¶»ñµÄ°üµÄÔ´µØÖ·£¬Äã¿ÉÒÔ´ÓÖв쿴˭ÔÚÊÔͼ¹¥»÷ÄãµÄÍøÂç¡£ÄãÒ²¿ÉÒÔͨ¹ýÏà¹ØÁ¬½ÓÀ´²ì¿´whoisÊý¾Ý¿â¡£\r\nËù²¶»ñµÄ°üµÄÄ¿µÄµØÖ·¡£\r\nÔ´ºÍÄ¿µÄ¶Ë¿Ú¡£\r\nÓëÌض¨Ð­ÒéÏà¹ØµÄ¸æ¾¯£¬ÈçTCP¡¢UDP¡¢ICMP¸æ¾¯¡£\r\n²éÕÒÌض¨ÀàÐ͵ĸ澯ºÍÈÕÖ¾ÌõÄ¿¡£\r\nƵÂÊ×î¸ßµÄ¸æ¾¯¡£\r\n¸æ¾¯Êý¾ÝµÄͼ±í£¬Ä¿Ç°Õâ¸ö¹¦ÄÜ»¹ÔÚʵÑéÖС£\r\n\r\nÔÚÏÂÃæµÄÆÁÄ»½ØͼÖÐÄã¿ÉÒÔÁ˽âһЩÖØÒªµÄÐÅÏ¢£¬µ«Í¨¹ýʵ¼ùÄã¿ÉÒÔÁ˽⣬ACIDÄܹ»Ìṩ¸øÄã¸ü¶àµÄÓÐÓÃÐÅÏ¢¡£\r\n6.3.1ЭÒéÏà¹ØÊý¾ÝÁбí\r\nÔÚÖ÷Ò³Ã棬Äã¿ÉÒÔµã»÷Ò»¸öЭÒéÀ´È¡µÃËù¼Ç¼µÄ¹ØÓÚÕâ¸öЭÒéµÄ°üµÄÐÅÏ¢¡£Í¼6-5ÏÔʾµÄÊǹØÓÚICMPЭÒéÐÅÏ¢µÄÆÁÄ»½Øͼ¡£ÔÚÆÁÄ»µÄÏÂÃ棬Äã¿ÉÒÔ¿´µ½15¸ö°üµÄÐÅÏ¢±»¼Ç¼µ½Êý¾Ý¿â¡£Äã¿ÉÒÔµã»÷ÆäÖÐÈÎÒâÒ»¸öÀ´»ñµÃ¹ØÓÚÕâ¸ö°üµÄÏêϸÐÅÏ¢¡£\r\n6.3.3¸æ¾¯ÐÅϢϸ½Ú\r\nͼ6-6ÏÔʾÁËij¸öÄãÔÚͼ6-5¿´µ½µÄICMP°üµÄϸ½Ú£¬ÆäÖаüº¬ºÜ¶à²¿·Ö£¬Ã¿²¿·ÖÏÔʾÁËÊý¾Ý°üµÄÒ»¸ö²ãÃ棬×îÉÏÃæµÄ²¿·ÖÊǹØÓÚÕâ¸ö¸æ¾¯µÄ×ÜÌåÐÅÏ¢¡£IP²¿·ÖÏÔʾÁËIPÍ·²¿µÄËùÓв¿·Ö£¬ICMPÍ·²¿ÏÔʾÁËICMPÊý¾Ý£¬½Ó×ÅÊÇÔغɡ£ÔغÉͬʱÒÔ16½øÖƺÍASCIIÂëÐÎʽ±íʾ¡£\r\n6.3.4 ²éѯ\r\nACIDµÄÒ»¸öÖØÒªÌØÐÔÊÇ¿ÉÒÔÓÃһЩ²ÎÊýÀ´²éѯÈÕÖ¾ºÍ¸æ¾¯£¬ÀýÈ磺\r\nij¸ö̽²âÆ÷\r\n¿ªÊ¼ºÍ½áÊøµÄʱ¼ä\r\nÔ´ºÍÄ¿µÄµØÖ·\r\nIPÍ·²¿µÄ²»Í¬×Ö¶Î\r\n´«Êä²ãЭÒé\r\nIP°üÔغÉÖеÄ×Ö·û\r\n\r\nÈçͼ6-7,Ö´ÐвéѯÊǷdz£¼òµ¥µÄ£¬ÄãÖ»Òªµã»÷¡°Query DB¡±¾Í¿ÉÒÔÏÔʾËù²éѯµÄÊý¾Ý¡£\r\nÀýÈ磬Èç¹ûÄãÏëÔÚËùÓеĸ澯ÐÅÏ¢Öвéѯ°üº¬×Ö·û¡°ATTACK RESPONSE¡±µÄ°ü£¬Äã¿ÉÒÔÏñͼ6-8ÄÇÑùÌî³äÐÅÏ¢¡£\r\n²éѯ½á¹ûÈç6-9Ëùʾ¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
85Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |ÏÔʾȫ²¿Â¥²ã
6.3.²éѯwhoisÊý¾Ý¿â\r\nÄã¿ÉÒÔµã»÷ÈκÎÒ»¸öIPµØÖ·²¢Ñ¡Ôñij¸öwhoisÊý¾Ý¿âÀ´²éѯwhoisÐÅÏ¢£¬ÀýÈçÄã¿ÉÒÔͨ¹ýλÓÚhttp://www.arin.netµÄARIN£¬ÀýÈçÍ ... 6.16.52µÄ²éѯ½á¹û¡£\r\nÔÚ´¦ÀíÍøÂ簲ȫÎÊÌâµÄʱºò£¬ÕâÖÖÐÅÏ¢ÊǷdz£ÓÐÓõģ¬ÍùÍùÔÚ·¢ÉúÏà¹ØÎÊÌâµÄµÚÒ»²½£¬ÄãÒª²éѯÈëÇÖÕßÊÇË­£¬ÕâÖÖÐÅÏ¢»á¸øÄãһЩÓÐÓõİïÖú¡£\r\n6.3.6²úÉúͼ±í\r\nACIDµÄ»æͼ¹¦ÄÜÈÔÈ»ÔÚʵÑéÖУ¬ACIDÌṩһ¸öÁ¬½ÓÓÃÀ´²úÉúͼ±í£¬ÄãÐèҪѡÔñÊý¾ÝºÍͼ±íÀàÐÍ¡£ÀýÈ磬Äã¿ÉÒÔ²úÉú×î½ü5ÌìµÄ¸æ¾¯µÄÏßͼ»òÕßÖ±·½Í¼£¬Í¼6-12ÊÇÒ»¸öʵÀý¡£\r\nPHPLOT±»ÓÃÀ´ÔÚºǫ́²úÉúͼ±í£¬ÄãÒ²¿ÉÒÔÓÃÆäËûÈçJPRAPHÀ´´úÌæËü¡£\r\n6.3.7SnortÊý¾Ý¿â´æµµ\r\nÊý¾Ý¿âsnort_archiveÓÃÀ´´ÓÖ÷Êý¾Ý¿â´æµµÊý¾Ý£¬ÀûÓÃACID£¬Äã¿ÉÒÔ½«¸æ¾¯´ÓÖ÷Êý¾Ý¿â¸´ÖÆ»òÕßÒƶ¯µ½´æµµÊý¾Ý¿â¡£\r\nÄã¿ÉÒÔÑ¡Ôñ½«Õû¸ö¹ØÓÚÊý¾Ý¿âµÄ²éѯ´æµµ»òÕߴ浵ijЩ²éѯ¡£\r\n6.3.8ACIDµÄ±í\r\nµ±ÄãµÚÒ»´ÎÔËÐÐACIDµÄʱºò£¬ËüÔÚSnortÊý¾Ý¿âÖд´½¨ÁËһЩ×Ô¼ºµÄ±í£¬ÕâЩ±íÓÃ×÷ACIDµÄ¹ÜÀí¹¦ÄÜ¡£\r\nÏÂÃæÊÇÔËÐÐACIDÇ°ºóMySQLµÄsnortÊý¾Ý¿âÖбíµÄ¶Ô±È£º\r\n֮ǰ£º\r\nmysql> show tables;\r\n+------------------+\r\n| Tables_in_snort |\r\n+------------------+\r\n| data |\r\n| detail |\r\n| encoding |\r\n| event |\r\n| flags |\r\n| icmphdr |\r\n| iphdr |\r\n| opt |\r\n| protocols |\r\n| reference |\r\n| reference_system |\r\n| schema |\r\n| sensor |\r\n| services |\r\n| sig_class |\r\n| sig_reference |\r\n| signature |\r\n| tcphdr |\r\n| udphdr |\r\n+------------------+

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
86Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |ÏÔʾȫ²¿Â¥²ã
19 rows in set (0.01 sec)\r\nmysql>\r\n\r\nÖ®ºó£º\r\nmysql> show tables;\r\n+------------------+\r\n| Tables_in_snort |\r\n+------------------+\r\n| acid_ag |\r\n| acid_ag_alert |\r\n| acid_event |\r\n| acid_ip_cache |\r\n| data |\r\n| detail |\r\n| encoding |\r\n| event |\r\n| flags |\r\n| icmphdr |\r\n| iphdr |\r\n| opt |\r\n| protocols |\r\n| reference |\r\n| reference_system |\r\n| schema |\r\n| sensor |\r\n| services |\r\n| sig_class |\r\n| sig_reference |\r\n| signature |\r\n| tcphdr |\r\n| udphdr |\r\n+------------------+\r\n23 rows in set (0.00 sec)\r\nmysql>\r\nÇ°Ãæ4¸ö±íÊÇACIDн¨Á¢µÄ¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
87Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |ÏÔʾȫ²¿Â¥²ã
6.4SnortSnarf\r\nSnortSnarfÊÇÁíÍâÒ»¸öÓÃweb½çÃæÀ´ÏÔʾSnortÊý¾ÝµÄ¹¤¾ß¡£Äã¿ÉÒÔÔÚhttp://www.silicondefense.com/so ... ¹ýwebä¯ÀÀÆ÷À´²ì¿´¡£\r\nsnortsnarf.pl /var/log/snort/alert -d /var/www/html/snortsnarf\r\nÏÂÃæµÄÃüÁî´ÓlocalhostÉϵÄMySQLÊý¾Ý¿âÌáÈ¡Êý¾Ý£¬ËüÓõ½ÁËÇ°ÃæÎÒÃÇÉèÖõÄÓû§ÃûºÍ¿ÚÁî¡£\r\nsnortsnarf.pl rr:rr78x@snort@localhost -d /var/www/html/snortsnarf\r\nÄã¿ÉÒÔÓÃcronÀ´Ê¹SnortSnarf¶¨ÆÚÔËÐУ¬Í¼6-15ÏÔʾÁËSnortSnarf²úÉúµÄÖ÷Ò³Ã棬ËüÌṩÁ˸澯ÐÅÏ¢µÄ»ù±¾Çé¿ö¡£\r\nͼ6-16ÊǹØÓÚij¸ö¸æ¾¯µÄÐÅÏ¢£¬Äã¿ÉÒÔµã»÷6-15ËùʾµÄ¸æ¾¯ÌõÄ¿À´µÃµ½ÕâÑùµÄÐÅÏ¢¡£\r\nͼ6-17ÊÇwhois²éѯµÄÆÁÄ»½Øͼ¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
88Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:43 |ÏÔʾȫ²¿Â¥²ã
7µÚÆßÕ ÆäËûһЩ¹¤¾ß\r\n±¾Õ½«½éÉÜÆäËûһЩ¹¤¾ß£¬²¢ÊÔͼÈÃÄãÁ˽âÈçºÎʹϵͳ¸ü¼Ó°²È«¡£ÏÂÃæÎÒÃÇÀ´½éÉÜÕâЩ¹¤¾ß¡£\r\n\r\nIDS ManagerÊÇ»ùÓÚWindowsͼÐνçÃæµÄSnort¹æÔòºÍÅäÖùÜÀí¹¤¾ß£¬Í¨¹ýËüÄã¿ÉÒÔ£º\r\n\r\n´ÓÒ»¸öÕýÔÚ¹¤×÷µÄSnort̽²âÆ÷ÉÏÏÂÔص±Ç°µÄÅäÖÃÎļþsnort.confºÍ¹æÔò¡£\r\nÐÞ¸ÄÅäÖÃÎļþºÍ¹æÔò¡£\r\n½«ÅäÖÃÎļþºÍ¹æÔòÉÏÔص½Ì½²âÆ÷ÉÏ¡£\r\n\r\nÓÃIDS ManagerÄã¿ÉÒÔ¹ÜÀí¶à¸ö̽²âÆ÷£¬Î¨Ò»Òª×¢ÒâµÄÊ£¬ÄãÐèÒªÔÚSnort̽²âÆ÷ÉÏÔËÐÐSSH·þÎñÆ÷¡£\r\n\r\nSnortSamÊÇÁíÍâÒ»¸ö¹¤¾ß£¬Ëü¿ÉÒÔ½«SnortÓë·À»ðǽÕûºÏÔÚÒ»Æð£¬Í¨¹ýËüºÍSnortÒ»Æð¹¤×÷£¬Äã¿ÉÒÔÐ޸ķÀ»ðǽµÄÉèÖᣵ«ÊÇÕâ¸ö¹¦ÄÜÈÔÓкܶàÕùÂÛ£¬ÒòΪËü¿ÉÄÜ»áʹ·À»ðǽÔâÊÜDos¹¥»÷¡£\r\n\r\n±¾ÕµÄÁíÍâÒ»¸öÂÛÌâÊÇ°²×°ACIDµÄweb·þÎñÆ÷µÄ°²È«ÐÔ£¬µ½ÏÖÔÚΪֹ£¬ÎÒÃÇ»¹Ã»ÓÐÉæ¼°µ½ÈçºÎ¼ÓÇ¿Õâ¸ö·þÎñÆ÷µÄ°²È«ÐÔ£¬ÈκÎÈ˶¼¿ÉÒÔ·ÃÎÊACID¿ØÖÆ̨²¢É¾³ýSnortËùÊÕ¼¯µÄÐÅÏ¢£¬ÎÒÃÇÉÔºó»á½â¾öÕâ¸öÎÊÌâ¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
89Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:43 |ÏÔʾȫ²¿Â¥²ã
7.1 SnrotSam\r\nSnortSam¿ÉÒÔʹSnortÓë×î³£¼ûµÄһЩ·À»ðǽЭͬ¹¤×÷£¬Ìṩ·À»ðǽ/IDSÕûºÏ½â¾ö·½°¸¡£ÔÚIDS̽²âµ½ÈëÇÖµÄʱºò£¬Ëü¿ÉÒÔÉèÖ÷À»ðǽÀ´×èÖ¹¶ñÒâµÄÊý¾Ý»òÕßIPµØÖ·¡£ÔÚhttp://www.snortsam.net/Äã¿ÉÒԵà ... ö¹¤¾ß°üÀ¨Á½¸ö²¿·Ö£º\r\n1¡¢        Ò»¸ö°²×°µ½Snort̽²âÆ÷ÉϵÄSnortÊä³ö²å¼þ¡£\r\n2¡¢        Ò»¸ö°²×°µ½¿¿½ü·À»ðǽ»ò·À»ðǽ±¾ÉíËùÔڵĻúÆ÷ÉϵĴúÀí¡£Snortͨ¹ý°²È«Á¬½ÓÓëÕâ¸ö´úÀíͨѶ¡£\r\nµ½Ä¿Ç°ÎªÖ¹£¬Õâ¸ö¹¤¾ßÖ§³ÖÒÔϵķÀ»ðǽ£º\r\n• »ùÓÚ IP filterµÄ·À»ðǽ\r\n• Checkpoint Firewall-1\r\n• Cisco PIX\r\n• Netscreen\r\n\r\nËüµÄÊä³ö²å¼þÐèÒªÓëSnortÒ»Æð±àÒ룬Ëü»áÌṩһЩеĹؼü×Ö£¬¿ÉÒÔÓÃÀ´¿ØÖÆ·À»ðǽµÄÐÐΪ¡£\r\nÔÚÒ»¸öÓÃCheckPiont·À»ðǽµÄµäÐÍ·½°¸ÖУ¬Äã¿ÉÒÔÔÚ·À»ðǽ±¾ÉíÔËÐÐSnortSam´úÀí¡£Èçͼ7-1Ëùʾ£¬Ò»¸öSnort̽²âÆ÷ÕýÔÚ¿ØÖÆÁ½¸öCheckPoint·À»ðǽ¡£CheckPoint·À»ðǽ¿ÉÒÔÔËÐÐÔÚLinux¡¢WindowsºÍÆäËûһЩËüËùÖ§³ÖµÄUnixϵͳÉÏ¡£\r\nÈç¹ûÄãµÄ·À»ðǽ²¢·ÇCheckPointÕâÑùµÄÈí¼þ·À»ðǽ£¬Äã¿ÉÒÔÔÚ¿¿½ü·À»ðǽµÄ»úÆ÷ÉÏÔËÐдúÀí£¬ÎªÕâ¸ö´úÀí°²×°Ä³ÖÖ²å¼þÀ´¿ØÖÆÒ»ÖÖÌض¨µÄ·À»ðǽ¡£ÀýÈ磬Èç¹ûÄãÐèÒª¿ØÖÆCisco·ÓÉÆ÷µÄ·ÃÎÊÁÐ±í£¬Äã¿ÉÒÔÔÚSnortSamÍøÕ¾ÉÏÏÂÔØÏà¹ØµÄ²å¼þ¡£²Î¼ûͼ7-2¡£\r\n¹ØÓÚSnortSamµÄÎĵµ¡¢Ê¾ÀýÒÔ¼°ÈçºÎ°²×°µÄÐÅÏ¢¿ÉÒÔÔÚËüµÄÍøÕ¾ÕÒµ½¡£µ«ÊÇÇë×¢ÒâÈç¹ûÅäÖò»µ±£¬ÓÃÕâÑùµÄ¹¤¾ß¿ÉÄܻᵼÖÂDoS¹¥»÷£¬ÀýÈ磬ijÈË·¢Ë͹¹ÔìÌØÊâµÄÐÅÏ¢£¬¿ÉÄÜ»áʹ·À»ðǽ×èÖ¹ºÏ·¨µÄ·þÎñÆ÷µÄͨѶ£¬±ÈÈçÄãµÄDNS·þÎñÆ÷µÈ¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
90Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:43 |ÏÔʾȫ²¿Â¥²ã
7.2 IDS Policy Manager\r\nIDS Policy ManagerÊÇ»ùÓÚWindowsͼÐνçÃæµÄ¹¤¾ßËü¿ÉÒÔÓÃÀ´¹ÜÀíSnortÅäÖÃÎļþºÍ¹æÔò¡£Äã¿ÉÒÔÔÚhttp:// activeworx.com/idspm/ÏÂÔØ¡£Æô¶¯Õâ¸öÈí¼þ£¬Äã¿ÉÒÔ¿´µ½Í¼7-3ËùʾµÄ´°¿Ú¡£\r\n¿ªÊ¼µÄʱºò£¬Õâ¸ö´°¿ÚÊǿհ׵ģ¬ÏÂÃæÓÐ3¸ö±êÇ©£¬·Ö±ðÊÇ£º\r\n\r\n¡°Sensor Manager¡±±êÇ©Ò³£¬ÏÔʾÄãÓÃÕâ¸ö¹¤¾ßËù¹ÜÀíµÄ̽²âÆ÷¡£¿ªÊ¼µÄʱºò£¬ÁбíÖÐûÓУ¬ÒòΪÄ㲢ûÓÐÌí¼ÓÈκÎ̽²âÆ÷¡£Æô¶¯µÄʱºò£¬Õâ¸öÒ³ÃæÊÇĬÈÏÒ³Ãæ¡£\r\n¡°Policy Manager¡±±êÇ©Ò³£¬ÏÔʾËùÅäÖõIJßÂÔ¡£²ßÂÔ°üÀ¨snort.conf²ÎÊýºÍ¹ØÓÚÕâ¸ö²ßÂԵĹæÔòÁÐ±í¡£\r\n¡°Logging¡±±êÇ©Ò³ÏÔʾÈÕÖ¾ÐÅÏ¢\r\n\r\nµã»÷±êÇ©¿ÉÒÔÇл»µ½ÏàÓ¦µÄ±êÇ©Ò³¡£Äã¿ÉÒÔµã»÷Sensor²Ëµ¥²¢Ñ¡Ôñ¡°Add Sensor¡±À´Ìí¼Ó̽²âÆ÷£¬»á³öÏÖÒ»¸öÈçͼ7-4ËùʾµÄµ¯³ö´°¿Ú£¬ÔÚÕâÀïÄã¿ÉÒÔÌî³ä¹ØÓÚ̽²âÆ÷µÄÐÅÏ¢¡£\r\n\r\nÄãÐèÒªÊäÈëÏÂÃæµÄÐÅÏ¢\r\n̽²âÆ÷µÄÃû³Æ£¬Äã¿ÉÒÔÌîдÄãËùÐèÒªµÄÃû×ÖÒÔ·½±ã¹ÜÀí\r\n̽²âÆ÷µÄIPµØÖ·\r\nIDS SystemÎı¾¿òÓÃÀ´Ö¸¶¨SnortµÄ°æ±¾£¬ÒòΪSnort²»Í¬µÄ°æ±¾µÄ²ÎÊýºÍ²å¼þÒÔ¼°¹Ø¼ü×ÖÓÐÒ»µã²»Í¬£¬Òò´ËÕâ¸öÐÅÏ¢µÄÕýÈ·ÐÔÒ²ÊDZȽÏÖØÒªµÄ¡£\r\n¡°Upload Information¡±°üÀ¨Ò»Ð©ºÍ̽²âÆ÷Ö®¼ä´«ÊäÎļþµÄ²ÎÊý¡£\r\nSCP·½Ê½ÊǵǼ̽²âÆ÷ÉϵÄSSH·þÎñÆ÷¡£¡°Upload Directory¡±Ö¸¶¨Snort̽²âÆ÷ÉϵÄsnort.confµÄλÖá£\r\n\r\nÔÚÊäÈëÕâЩÐÅÏ¢ÒÔºóµã»÷OK¾ÍÌí¼ÓÁËÒ»¸ö̽²âÆ÷¡£ºóÃæµÄµÚÒ»ÏîÈÎÎñ¾ÍÊÇ´ÓÄã¸Õ²ÅÌí¼ÓµÄ̽²âÆ÷ÉÏÃæÏÂÔزßÂÔ¡£ÔÚSensor²Ëµ¥ÖÐÑ¡ÔñDownload Policy from SensorÀ´ÊµÏÖÕâ¸öÄ¿µÄ¡£ÏÂÔØÍê³Éºó£¬µã»÷´°¿ÚÏ·½µÄPolicy Manager±êÇ©£¬Äã¿ÉÒÔ¿´µ½µ±Ç°µÄ²ßÂÔµÄÁÐ±í²¢ÔÚÕâÀï±à¼­²ßÂÔ£¬Ë«»÷²ßÂÔÃû×Ö£¬¾Í³öÏÖÒ»¸ö²ßÂԱ༭´°¿Ú£¬Èçͼ7-5Ëùʾ¡£
ÄúÐèÒªµÇ¼ºó²Å¿ÉÒÔ»ØÌû µÇ¼ | ×¢²á

±¾°æ»ý·Ö¹æÔò ·¢±í»Ø¸´

  

±±¾©Ê¢ÍØÓÅѶÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾. °æȨËùÓÐ ¾©ICP±¸16024965ºÅ-6 ±±¾©Êй«°²¾Öº£µí·Ö¾ÖÍø¼àÖÐÐı¸°¸±àºÅ£º11010802020122 niuxiaotong@pcpop.com 17352615567
δ³ÉÄê¾Ù±¨×¨Çø
Öйú»¥ÁªÍøЭ»á»áÔ±  ÁªÏµÎÒÃÇ£ºhuangweiwei@itpub.net
¸ÐлËùÓйØÐĺÍÖ§³Ö¹ýChinaUnixµÄÅóÓÑÃÇ ×ªÔر¾Õ¾ÄÚÈÝÇë×¢Ã÷Ô­×÷ÕßÃû¼°³ö´¦

Çå³ý Cookies - ChinaUnix - Archiver - WAP - TOP