ÔõÑùÔÚLinuxÉÏÉèÖø߿ÉÓõÄÍøÂçÇå¾²Éó¼Æ
ÔõÑùÔÚlinuxÉÏÉèÖø߿ÉÓõÄÍøÂçÇå¾²Éó¼Æ
СÐò£º
ÔÚÄ¿½ñÐÅÏ¢Çå¾²ÐÎÊÆÑÏËàµÄÅä¾°Ï£¬ÍøÂçÇå¾²Éó¼Æ³ÉΪÁËÒ»¸öÖ÷ÒªµÄ»·½Ú£¬Ëü¿ÉÒÔͨ¹ýÍøÂçºÍÆÊÎöÍøÂçÖеÄÁ÷Á¿Êý¾Ý£¬¼à¿ØÍøÂçµÄʹÓÃÇéÐΣ¬·¢Ã÷ºÍÌá·ÀÍøÂç¹¥»÷£¬°ü¹ÜÍøÂçµÄÇå¾²ÐÔºÍÎȹÌÐÔ¡£Í¬Ê±£¬ÎªÁËÓ¦¶Ô´ó¹æÄ£µÄÍøÂçÁ÷Á¿ºÍÊý¾Ý´¦Öóͷ£ÐèÇó£¬ÎÒÃÇÐèÒªÉèÖø߿ÉÓõÄÍøÂçÇå¾²Éó¼Æϵͳ¡£±¾ÎĽ«´ÓÒÔϼ¸¸ö·½ÃæÏÈÈÝÔõÑùÔÚLinuxϵͳÉÏÉèÖø߿ÉÓõÄÍøÂçÇå¾²Éó¼Æ¡£
Ò»¡¢´î½¨LinuxÇéÐÎ
Ê×ÏÈ£¬ÎÒÃÇÐèÒª´î½¨Ò»¸öÎȹ̿ɿ¿µÄLinuxÇéÐΡ£ÔÚLinuxÉÏ¿ÉÒÔÑ¡ÔñʹÓÃCentOS¡¢UbuntuµÈ³£¼ûµÄLinux¿¯Ðа档ÒÔÏÂʾÀýÒÔCentOSΪÀý¡£
×°ÖÃCentOS²Ù×÷ϵͳ
Ê×ÏÈ£¬ÏÂÔØCentOS²Ù×÷ϵͳµÄ¾µÏñÎļþ£¬²¢Ê¹ÓÃUÅÌ»òÐéÄâ»úµÈ·½·¨×°ÖÃϵͳ¡£×°ÖÃÍê³Éºó£¬È·±£ÏµÍ³°æ±¾ÊÇ×îеģ¬²¢¸üÐÂϵͳ°ü¡£
×°ÖÃÐëÒªµÄÈí¼þ°ü
ÔÚ×°ÖÃCentOS²Ù×÷ϵͳºó£¬ÎÒÃÇÐèҪװÖÃһЩÐëÒªµÄÈí¼þ°ü£¬Èçsnort¡¢suricata¡¢tcpdumpµÈ¡£¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÀ´×°Öãº
sudo yum install snort suricata tcpdump
µÇ¼ºó¸´ÖÆ
ÉèÖÃÍøÂçÇéÐÎ
ÔÚÍøÂçÇå¾²Éó¼ÆÖУ¬ÎÒÃÇÐèÒª°ü¹ÜÍøÂçµÄ¿É´ïÐÔ¡£Òò´Ë£¬ÐèÒªÉèÖÃ׼ȷµÄÍøÂçÇéÐΡ£¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÀ´ÉèÖÃÍøÂçÇéÐΣº
sudo ifconfig eth0 192.168.1.10 netmask 255.255.255.0
µÇ¼ºó¸´ÖÆ
ÆäÖУ¬eth0ÌåÏÖÍø¿¨Ãû³Æ£¬192.168.1.10ÌåÏÖÖ÷»úIPµØµã¡£
¶þ¡¢ÉèÖø߿ÉÓõÄÍøÂçÇå¾²Éó¼Æϵͳ
ÔڴºÃLinuxÇéÐκó£¬ÎÒÃÇÐèÒªÉèÖø߿ÉÓõÄÍøÂçÇå¾²Éó¼Æϵͳ¡£ÒÔÏÂʾÀýÒÔsnortΪÀý¡£
×°Öü°ÉèÖÃsnort
Ê×ÏÈ£¬ÎÒÃÇÐèҪװÖÃsnort£¬²¢ÉèÖÃÆäÏà¹Ø¹æÔò¡£¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÀ´×°Öãº
sudo yum install snort
µÇ¼ºó¸´ÖÆ
×°ÖÃÍê³Éºó£¬ÎÒÃÇÐèÒªÏÂÔØ×îеĹæÔò¼¯£¬²¢ÉèÖÃsnort.conf¡£¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÀ´ÏÂÔعæÔò¼¯£º
wget https://www.snort.org/rules/community -O snort.rules.tar.gz tar -xvzf snort.rules.tar.gz -C /etc/snort/rules/
µÇ¼ºó¸´ÖÆ
È»ºó£¬±à¼snort.confÎļþ£¬Ìí¼Ó¹æÔò¼¯Â·¾¶£º
sudo vi /etc/snort/snort.conf # Ìí¼ÓÒÔÏÂÄÚÈÝ include $RULE_PATH/snort.rules
µÇ¼ºó¸´ÖÆ
ÉèÖÃsnort¼¯Èº
ΪÁËʵÏָ߿ÉÓÃÐÔ£¬ÎÒÃÇÐèÒªÉèÖÃsnort¼¯Èº¡£¿ÉÒÔͨ¹ýÒÔÏ°취À´ÉèÖãº
Ê×ÏÈ£¬½«¼¯ÈºÖеÄÖ÷»ú¶¼Ìí¼Óµ½Í³Ò»¸öÍøÂçÖУ¬²¢°ü¹ÜËüÃÇÖ®¼ä¿ÉÒÔÕý³£Í¨Ñ¶¡£
È»ºó£¬ÔÚÿ¸öÖ÷»úÉÏÉèÖÃsnort.confÎļþ£¬ÆôÓü¯Èº¹¦Ð§£º
sudo vi /etc/snort/snort.conf # Ìí¼ÓÒÔÏÂÄÚÈÝ config cluster: mac eth1
µÇ¼ºó¸´ÖÆ
ÆäÖУ¬eth1ÌåÏÖ¼¯ÈºÍ¨Ñ¶µÄÍø¿¨Ãû³Æ¡£
×îºó£¬ÖØÆôsnortЧÀÍ£¬ÔÚÿ¸öÖ÷»úÉÏ»®·ÖÖ´ÐÐÒÔÏÂÏÂÁ
sudo systemctl restart snort
µÇ¼ºó¸´ÖÆ
Èý¡¢ÊµÏÖÍøÂçÇå¾²Éó¼Æ
ÔÚÉèÖúø߿ÉÓõÄÍøÂçÇå¾²Éó¼Æϵͳºó£¬ÎÒÃÇ¿ÉÒÔ×îÏȾÙÐÐÍøÂçÇå¾²Éó¼ÆÊÂÇéÁË¡£ÒÔÏÂʾÀýÒÔsnortΪÀý¡£
Æô¶¯snort
Ê×ÏÈ£¬ÎÒÃÇÐèÒªÆô¶¯snortЧÀÍ¡£¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÀ´Æô¶¯£º
sudo systemctl start snort
µÇ¼ºó¸´ÖÆ
¼à¿ØÍøÂçÁ÷Á¿
snort¿ÉÒÔʵʱ¼à¿ØÍøÂçÁ÷Á¿£¬²¢Æ¾Ö¤Ô¤½ç˵µÄ¹æÔò¼¯À´¼ì²â¶ñÒâÔ˶¯¡£¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÀ´¼à¿ØÁ÷Á¿£º
sudo snort -i eth0 -c /etc/snort/snort.conf
µÇ¼ºó¸´ÖÆ
ÆäÖУ¬eth0ÌåÏÖÐèÒª¼à¿ØµÄÍø¿¨Ãû³Æ¡£
ÆÊÎöÉó¼ÆЧ¹û
snort»á½«¼ì²âµ½µÄ¶ñÒâÔ˶¯Ð´Èëµ½ÈÕÖ¾ÎļþÖС£ÎÒÃÇ¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÀ´Éó²éÈÕÖ¾£º
sudo tail -f /var/log/snort/alert
µÇ¼ºó¸´ÖÆ
ÆäÖУ¬/var/log/snort/alertΪÈÕÖ¾Îļþ·¾¶¡£
×ܽ᣺
±¾ÎÄÏÈÈÝÁËÔõÑùÔÚLinuxϵͳÉÏÉèÖø߿ÉÓõÄÍøÂçÇå¾²Éó¼Æϵͳ¡£Í¨¹ý´î½¨LinuxÇéÐΣ¬²¢ÉèÖÃÐëÒªµÄÈí¼þ°üºÍÍøÂçÇéÐΣ¬ÎÒÃÇ¿ÉÒԴÎȹ̿ɿ¿µÄ»ù´¡ÇéÐΡ£È»ºó£¬Í¨¹ý×°ÖúÍÉèÖÃsnortµÈ¹¤¾ß£¬ÎÒÃÇ¿ÉÒÔʵÏָ߿ÉÓõÄÍøÂçÇå¾²Éó¼Æ¡£×îºó£¬ÎÒÃÇ¿ÉÒÔÆô¶¯snortЧÀÍ£¬¼à¿ØÍøÂçÁ÷Á¿£¬²¢ÆÊÎöÉó¼ÆЧ¹û¡£Ö»ÓкÏÀíÉèÖø߿ÉÓõÄÍøÂçÇå¾²Éó¼Æϵͳ£¬²Å»ª¸üºÃµØ·¢Ã÷ºÍÌá·ÀÍøÂç¹¥»÷£¬°ü¹ÜÍøÂçµÄÇå¾²ÐÔºÍÎȹÌÐÔ¡£
ÒÔÉϾÍÊÇÔõÑùÔÚLinuxÉÏÉèÖø߿ÉÓõÄÍøÂçÇå¾²Éó¼ÆµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡