Jump to content
Wubi

Network Defense with The Security Onion

Recommended Posts

Posted



TekTip - Ep9 - The Security Onion: created by Doug Burks
Security Onion

Description: Security Onion is a Linux distro for IDS (Intrusion Detection) and NSM (Network Security Monitoring). It's based on Xubuntu 10.04 and contains Snort, Suricata, Sguil, Squert, Snorby, Bro, NetworkMiner, Xplico, and many other security tools. The easy-to-use Setup wizard allows you to build an army of distributed sensors for your enterprise in minutes!

Security Onion is THE distro for Network Monitoring in the same way that Backtrack is for pentesting.

Uses: Malware analysis, signature developement, honeynet/lab, home or small office.

1. Download iso and install.
*Need a GB of RAM per interface you are monitoring
**Installation is quick. Less then 10 minutes
***Currently based off of 10.04. Roadmap shows 64 bit based on 12.04 should be out soon.

2. If using Quick Mode installaion, TSO will monitor all interfaces

3. Monitor a network, or generate traffic. You can find tons of pcaps to replay at: https://code.google.com/p/security-onion/wiki/Pcaps
tcpreplay -i eth0 -t /tmp/bittorent.pcap
-i : use this option to select the interface to replay the traffic to.
-t: use this option to replay the packets as fast as possible
then select your pcap, cap, dump, or log

1aN0rmus@tekdefense.com
ww.tekdefense.com


Sursa YouTube

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...