Quotations
Sun Tzu's The Art of War (孙子兵法) says "If you know your enemies and know yourself, you will not be put at risk even in a hundred battles. If you only know yourself, but not your opponent, you may win or may lose. If you know neither yourself nor your enemy, you will always endanger yourself." (知彼知己,百战不殆;不知彼而知己,一胜一负;不知彼,不知己,每战必殆。) [source : Wikipedia]
Sun Tzu's The Art of War also says "All warfare is based on deception. Hence, when we are able to attack, we must seem unable; when using our forces, we must appear inactive; when we are near, we must make the enemy believe we are far away; when far away, we must make him believe we are near." (兵者,诡道也。故能而示之不能,用而示之不用,近而示之远,远而示之近。) [source : Wikipedia]
Reconnaissance
Most internet attack activities based on recon on the target. Recon can be conducted by active and passive methods. Active recon will cause a lot of noise to the target as it will collect information from the target directly while passive recon does not.
Once attackers gathered valuable information about the target, such as running services and versions on the target. They will launch exploits when there are vulnerable services running on the target. Once success, the target will be compromised and under the control of the attackers.
On the other hand, if there is no running vulnerable services on the target, attackers may launch social engineering attacks against the target, such as phishing mails, phishing sites, phishing phone calls, phishing downloads and etc. Social engineering may lead to compromise of the target as a result.
The captioned mention attacks can be based on randomly selected target or targeted victim. Furthermore, some attacks are directly by botnets which randomly selecting the targets and aimed to the vulnerable running services. Botnet attacks also have active recon stage as mentioned before.
Possible Defense
Besides some of social engineering attacks, we all know that all almost all attacks are following by recon. If attackers cannot get any valuable information from us, we can delay or even prevent the attack.
We all know that nmap can obtain information of the running services on the opening ports. If we can block nmap scanning from the beginning, attackers are required to guess which ports are opened and which services and versions are running on that ports. They cannot go further when they have no valuable information about us. If so, we can delay or even prevent the attacks. However, social engineering attacks may be launched soon by the attackers.
Commercial Solution
Some anti-virus for Windows system and some Unified Threats Management System (UTM) as well as some Intrusion Prevention System (IPS) can block port scanning. However, some of them failed to detect and block the nmap scan when it is scanning with special command flags. Meanwhile, anti-virus software and UTM as well as IPS may require to subscribe the signatures annually. In addition, commercial UTM and IPS are very expensive. It may cost a lot when long run.
Open Source Solution
Suricata and Snort are very famous Intrusion Detection and Prevention engines (IDPS). They are running based on blacklisting. Those blacklists are rules to alert or block the traffic when the traffic meets the criteria. There are open rules and paid rules available in the market. Some IDPS engines users can write their own rules to meet their requirements. However, some of the rules are written wrongly that causing false positive alert or even cannot detect the activities.
Not everyone is IDPS expert. Setting up a working Suricata or Snort appliance is painful. Users are required to troubleshoot all the problems that they are encountered. Sometimes are hardware limitations. Sometimes are false positive alerts/drops. Sometimes are IDPS engines limitations.
Plug, Play and Forget!
Almond Croissants is an open source IDPS based on Suricata engine. It is released under GPLv3 by Samiux since 2012. It is well tested on Windows, macOS, Linux, Apple iOS and Android. Engine and rules are updated automatically when they are available. Users are not required to be very familiar with IDPS. It not only can detect and block nmap scanning without pain but also have many outstanding features that most IDPS omitted. It is tasty and really "Plug, Play and Forget!"
That's all! See you.
Open Source is a great idea and it has changed the world!
Open Source forever ....
While you do not know attack, how can you know about defense? (未知攻,焉知防?)
Do BAD things .... for the RIGHT reasons -- OWASP ZAP
It is easier to port a shell than a shell script. -- Larry Wall
Most of you are familiar with the virtues of a programmer. There are three, of course: laziness, impatience, and hubris. -- Larry Wall
为天地立心, 为生民立命, 为往圣继绝学, 为万世开太平。 -- 王炜
Showing posts with label Snort. Show all posts
Showing posts with label Snort. Show all posts
Tuesday, December 13, 2016
Monday, June 15, 2015
REVIEW : Shield - Intrusion Prevention System for Home Users

What is Shield?
Shield is a very small device that can protect your home and small business network from being attack by malicious hackers. The attacks include viruses, scams, phishing, website and browser exploits as well as operating system and application exploits. Shield protects your incoming and outgoing traffic. Even your system or network is compromised before using Shield, malicious hackers cannot control and access your system or network any further when Shield is implemented. Shield is also protecting your system or network from being scanning of vulnerabilities. That is excellent for preventing your system or network from being attack.
Shield acts as Intrusion Prevention System (IPS) or Unified Threat Management System (UTM). When it acts as IPS, the core engine is Suricata (Intrusion Detection and Prevention System). It is the simplest way to implement the device and its throughput is more than 1 Gbps. When it acts as UTM, its core engine is Snort (Intrusion Detection and Prevention System). This mode has a lot of features, such as web content filtering, anti-virus, VPN, QoS and etc. However, the slower throughput is the drawback for UTM mode.
Suricata and Snort are using Emerging Threats Open Rules for the operation. Emerging Threats Open Rules include malicious IP addresses, virus signatures, exploit signatures and attack signatures. It also include scanner signatures. According to Suricata developers, the maximum throughput of Suricata is more then 30 Gbps.
Shield includes a free lifetime subscription to stay up-to-date against the latest threats with automatic essential security updates. There is no number of user limitation in the device. It is designed for general users with no professional training in Information Security. It is very easy to setup and use. Plug, Play and Forget!
Business or DIY
There are some UTM or IDS/IPS available in the market. Those devices are developed for business and the prices are not reasonable for home or small business users. The cost will be over $1,000-USD. Meanwhile, the power consumption of those devices would be higher than Shield. Shield is only between 10W and 15W. Commercial UTM or IDS/IPS will have number of users restriction as well as cost for subscription annually of the rules and services.
On the other hand, we can build an UTM with Untangle; or, we can build a Suricata or Snort based IDS/IPS without paying for the software. However, the cost of hardware would be higher than the Shield for sure. For example, this motherboard costs about $399.99-USD. You also need to purchase hard drive, memory and computer case too. The power consumption for this hardware is between 35W to 80W. Shield would be cost around $300-USD only.
Recommended Setup
We suggest to plug Shield between your modem (if any) or Internet Service Provider (ISP) and router (wired or wireless) in Bridge Mode for excellent performance and protection.
If you do not have any router or you have a slower internet connection and the speed of the intranet is less than 1 Gbps, Router Mode can be implemented. The setup for Bridge and Router Modes are very easy and simple. No skill is required, believe me.
IPS (Bridge Mode)
UTM (Router Mode)
Technical Specifications
- 2 x 1.0 GHz MIPS64 CPU
- 1 GB DDR3 RAM
- 4 GB eMMC
- 3 x 1 GB Ethernet
- 1 x RJ45 Serial console port
- 5 x 3.5 x 1 inches
- between 10W and 15W power consumption
Features
Router Mode and Gateway Mode (UTM)
- Snort Engine
- Emerging Threats Rules
- Intrusion Prevention
- Network Anti-Virus
- NAT Firewall
- Content Filtering
- Web Proxying
- Dynamic DNS
- SSLVPN
- Quality of Service
- Graphical Web User Interface
- Realtime Traffic Monitor
- Realtime Connection Monitor
- Advanced and Basic Mode
- 10 Mbps throughput
- Plus More!
Bridge Mode (IPS)
- Suricata Engine
- Emerging Threats Rules
- Intrusion Prevention
- Graphical Web User Interface
- Realtime Traffic Monitor
- Realtime Connection Monitor
- Advanced and Basic Mode
- 40 Mbps throughput
Conclusion
Shield is well designed and the performance will not worse than other similar devices in the market. However, the price is rivalry. It is the first IDS/IPS/UTM for home users and small business. Being a Shield beta tester and developer of Croissants, I am fully satisfied with the performance, price, size and power consumption of Shield. It is really can be "Plug, Play and Forget!". Recommended!
That's all! See you.
Review in Chinese version
Tuesday, September 24, 2013
HOWTO : High Performance IDS/IPS with SmoothSec 3.4
The following Intrusion Detection/Prevention System (IDS/IPS) setup is using AF_PACKET with SmoothSec 3.4. The following setup is for low traffic flow home and SOHO users (or you can say that it is a Proof-of-Concept). If your traffic is heavy, please consider to use a high-end hardware.
(A) Hardware
IDS/IPS -
Motherboard - Intel Desktop Board D510MO CPU - Intel Atom D510 (Dual-core with HT) RAM - 4GB (2 x 2GB) Hard Drive - 320GB Network Card 0 (eth0) - Onboard Gigabit Network Card 1 (eth1) - TP-Link TG-3269 Gigabit PCI Network Adapter (with low profile) Network Card 2 (eth2) - D-Link DUB-E100 USB 2.0 Fast Ethernet Adapter (up to 200MB) * You can select (1) Level One USB-0401 USB Gigabit Ethernet Adapter or (2) PCi USB 3.0 Gigabit LAN Adapter UE-1000T-G3 for eth2. However, you need to compile and install the driver yourself. Update : If you are using Backports latest kernel, the Level One USB-0401 and PCi UE-1000T-G3 are workable out of the box. Router - Motherboard - Intel Desktop Board D510MO CPU - Intel Atom D510 (Dual-core with HT) RAM - 4GB (2 x 2GB) Hard Drive - 320GB Network Card 0 (eth0) - Onboard Gigabit Network Card 1 (eth1) - TP-Link TG-3269 Gigabit PCI Network Adapter (with low profile) (B) Software IDS/IPS - Operating System - Debian 7.0 (Wheezy) IDS/IPS Pre-configure system - SmoothSec 3.4 (64-bit) IDS/IPS Engine - Snort (or Suricata) Unified2 Spooler - Pigsty Web Interface - Snorby Rules Management - PulledPork Router - Operating System - Untangle 9.4.2 (64-bit) * Basically, Untangle is a router and Unified Threat Management System (UTM). (C) Hardware Setup
After installed SmoothSec, type the following :
That's all! See you.
Motherboard - Intel Desktop Board D510MO CPU - Intel Atom D510 (Dual-core with HT) RAM - 4GB (2 x 2GB) Hard Drive - 320GB Network Card 0 (eth0) - Onboard Gigabit Network Card 1 (eth1) - TP-Link TG-3269 Gigabit PCI Network Adapter (with low profile) Network Card 2 (eth2) - D-Link DUB-E100 USB 2.0 Fast Ethernet Adapter (up to 200MB) * You can select (1) Level One USB-0401 USB Gigabit Ethernet Adapter or (2) PCi USB 3.0 Gigabit LAN Adapter UE-1000T-G3 for eth2. However, you need to compile and install the driver yourself. Update : If you are using Backports latest kernel, the Level One USB-0401 and PCi UE-1000T-G3 are workable out of the box. Router - Motherboard - Intel Desktop Board D510MO CPU - Intel Atom D510 (Dual-core with HT) RAM - 4GB (2 x 2GB) Hard Drive - 320GB Network Card 0 (eth0) - Onboard Gigabit Network Card 1 (eth1) - TP-Link TG-3269 Gigabit PCI Network Adapter (with low profile) (B) Software IDS/IPS - Operating System - Debian 7.0 (Wheezy) IDS/IPS Pre-configure system - SmoothSec 3.4 (64-bit) IDS/IPS Engine - Snort (or Suricata) Unified2 Spooler - Pigsty Web Interface - Snorby Rules Management - PulledPork Router - Operating System - Untangle 9.4.2 (64-bit) * Basically, Untangle is a router and Unified Threat Management System (UTM). (C) Hardware Setup
Internet ---- Router ---- SmoothSec ---- Switch ---- Personal Computers
Router -- eth0 connect to Internet; eth1 connect to SmoothSec
SmoothSec -- eth0 connect to Router; eth1 connect to Switch (uplink or port 1); eth2 connect to Switch (any port at 2 to 4)
* You can use any router to replace Untangle.
(D) Installation of SmoothSec
Download SmoothSec 3.4 at here or here.
Make sure the SmoothSec box can surf the internet; otherwise, installation will be failed. Or, you may re-arrange the cables when necessary.
Updated : Since the scripts for 3.4 has been updated to 3.4.1, you should follow the below link to upgrade the script to 3.4.1.
Upgrade to scripts version 3.4.1
The scripts 3.4.1 will install Backports newest kernel instead of Unstable kernel for Suricata IPS mode with AF_PACKET.
After installed SmoothSec, type the following :
smoothsec.first.setup
Snort -
Select "ips-standard" and following the instruction to install. Please also refer to here for the configuration of the config file. Make sure "AF_ENGINE" is set to "snort". The rules are "et" by default.
After install, reboot your box.
Suricata -
Select "ips-standard" and following the instruction to install. Please also refer to here for the configuration of the config file. Make sure "AF_ENGINE" is set to "suricata". The rules are "et" by default.
A new Linux kernel 3.10.2 will be installed at the end.
After install, reboot your box.
(E) Configuration of IDS/IPS
You may need to disable or/and drop some rules (sid).
Snort -
You may need to configure the /etc/snort/snort.conf :
nano /etc/snort/snort.conf
For example, the subnet is 192.168.1.0/24.
Replace "ipvar HOME_NET any" with "ipvar HOME_NET [192.168.1.0/24]"
Replace "ipvar EXTERNAL_NET any" with "ipvar EXTERNAL_NET ![192.168.1.0/24]"
Restart Snort :
/etc/init.d/snort restart
Disable rules :
nano /etc/pulledpork/snort/disablesid.conf
Drop rules :
nano /etc/pulledpork/snort/dropsid.conf
After doing that, reload the rules :
smoothsec.snort.rules.update
Suricata -
Disable rules :
nano /etc/pulledpork/suricata/disablesid.conf
Drop rules :
nano /etc/pulledpork/suricata/dropsid.conf
After doing that, reload the rules :
smoothsec.suricata.rules.update
* If the rule is too long to disable or drop, you may consider to edit "modifysid.conf". For example, to disable and drop the following rule :
To disable the rule :
2013437 "alert" "##alert";
To drop the rule :
2013437 "alert" "drop";
(F) Configuration of Snorby
For example, the sensor IP address is 192.168.1.180.
Point your browser to https://192.168.1.180. Enter the username and password of Snorby.
Setup the Snorby according to SmoothSec WiKi.
* If you want to sent your Snorby reports by Postfix, you need to install yourself and configure it then.
sudo apt-get install postfix
Select "Internet Site" when asked.
(G) IDS/IPS Tuning
There may be some false positive records. You need to tune the setting by adding the sid to the disablesid.conf or dropsid.conf when necessary. When use with dropsid.conf, yon may need to set firewall at Router to make the job done.
(H) Remarks
In the captioned setting, the SmoothSec acts as IDS and IPS in one box.
If you want to install IDS only, your SmoothSec only requires one Network Card which is connected to Switch.
In addition, SmoothSec 3.4 comes with Distributed IDS/IPS which allows you to deploy multi-sensors with one control panel (Snorby).
Furthermore, you can also reset your box to the fresh install environment :
smoothsec.reset
When using Snorby, you may need to browse for the rules sid. This link is for the rules lookup.
Make sure you create an empty file namely restart.txt under /var/www/snorby/tmp :touch /var/www/snorby/tmp/restart.txtThat's all! See you.
Monday, September 09, 2013
HOWTO : 15 Minutes to Deploy an IDS with SmoothSec 3.4
You can deploy your IDS (Intrusion Detection System) to your LAN within 15 minutes with SmoothSec 3.4. You can install SmoothSec 3.4 in virtual machine, such as VMWare, VirtualBox or Parallels.
The virtual machine is required at least one CPU, 1GB RAM and 8G+ HDD to run the IDS. The NIC is a bridged adaptor.
That's all! See you.
Sunday, September 08, 2013
HOWTO : 30 minutes to deploy a distributed IDS with SmoothSec 3.4
Distributed IDS is one of the features of SmoothSec 3.4. It allows you to monitor more than one sensor with one web interface (Snorby). Furthermore, the distributed IDS can be deployed by virtual machine, such as VMWare, VirtualBox and Parallels.
The basic virtual machines (console and sensor) requirement is 1 CPU, 1GB RAM and 8GB+ virtual storage.
You can install up to 2 IDS engines, Snort and Suricata in one box or either one of them.
Hints for installation
When installing sensor, you will be asked for ssh passphrase, you just press "Enter" and leave it empty. The path of the ssh key pairs should be default (nothing to change).
That's all! See you.
Saturday, July 02, 2011
Does Snort really protect your network?
Before watching the video below which is prepared by TOX1C, I always think that Snort is powerful and protective. Now, I know that Snort cannot protect your network from being hacked by skilled hackers.
Enjoy!
Enjoy!
Pissing on Snort with Metasploit from T0X1C on Vimeo.
Labels:
Metasploit,
Snort
Subscribe to:
Posts (Atom)
