
OSSIMïŒãªãŒãã³ãœãŒã¹ã»ãã¥ãªãã£æ
å ±ç®¡çïŒ-管çãå¶åŸ¡ãæ
å ±ã»ãã¥ãªãã£ã®ã·ã¹ãã ã
OSSIMã®ããã®ãŸãŸãã«ã¯ã次ã®ãããªæ©èœãå«ãŸããŸãã
- ã€ãã³ãã®åéãåæãçžé¢-SIEM
- ãã¹ã䟵å
¥æ€ç¥ã·ã¹ãã ïŒHIDSïŒ -OSSEC
- ãããã¯ãŒã¯äŸµå
¥æ€ç¥ã·ã¹ãã ïŒNIDSïŒ -Suricata
- ã¯ã€ã€ã¬ã¹äŸµå
¥æ€ç¥ã·ã¹ãã ïŒWIDSïŒ -Kismet
- ãã¹ãç£èŠ-Nagios
- ãããã¯ãŒã¯ç°åžžåæ-P0f ã PADS ã FProbe ã Arpwatchãªã©
- è匱æ§ã¹ãã£ããŒ-OpenVAS
- OSSIMãŠãŒã¶ãŒéã®æã匷åãªè
åšæ
å ±äº€æã·ã¹ãã -OTX
- ããŸããŸãªå€éšããã€ã¹ããã³ãµãŒãã¹ããã®ãã°ã®è§£æããã³çžé¢ã®ããã®200以äžã®ãã©ã°ã€ã³
ãŸããã
ãã®èšäºã§ã¯ãäž»ã«OSSIMã®ã€ã³ã¹ããŒã«ãåæã»ããã¢ãããããã³æ§æã«çŠç¹ãåœãŠãŸããæ©èœã«é¢ãããã¹ãŠã®æ
å ±ã¯ã
å
¬åŒWebãµã€ãããå
¥æã§ããŸãããŸãã¯ããã®ãããªãåç
§ããŠãã ããã
AlienVaultã«ã¯ãç¡æã®OSSIMãšããé«åºŠãªããŒãžã§ã³ã®2ã€ã®è£œåãUSMããããŸããéãã¯
ãã®ãªã³ã¯ã§ç¢ºèªã§ããŸãã
ããŸããšããŠããã®èšäºã®æåŸã®ç« ã§ã¯ãOSSIMãšArcemight SIEMã·ã¹ãã ã®çµ±åã«é¢ããæ
å ±ãæ²èŒããŸããã
ç®æ¬¡
OSSIMãã€ã³ã¹ããŒã«OSSIMã®æ§æäœ¿çšãããœãŒã¹OSSIMãã€ã³ã¹ããŒã«
ãªãŒãã³ãœãŒã¹ã®SIEMã·ã¹ãã ã®ã€ã³ã¹ããŒã«ã¯ãDebianãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšãã¹ãŠã®å¿
èŠãªãã¬ã€ã³ã¹ããŒã«ã³ã³ããŒãã³ããšã¢ãžã¥ãŒã«ãå«ãæ¢è£œã®ã€ã³ã¹ããŒã«ã€ã¡ãŒãžã䜿çšããŠè¡ãããŸãã
OSSIMãã€ã³ã¹ããŒã«ããã«
ã¯ããªã³ã¯ãéãå¿
èŠããã
ãŸã ããã®åŸãOSSIMãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ææ°ããŒãžã§ã³ã®ããŠã³ããŒããããã«éå§ãããŸãã
VMware ESXiã«ã€ã³ã¹ããŒã«ããŸãã
ESXiã»ããã¢ãã
ãŸããESXièªäœãæ§æããå¿
èŠããããŸããã€ãŸãã
ãèãåããªããã¢ãŒãïŒç¡å·®å¥ã¢ãŒãïŒã§åäœããã€ã³ã¿ãŒãã§ã€ã¹ãæ§æããå¿
èŠããããŸãã ãããã¯ãŒã¯ç£èŠãèšå®ããã«ã¯ãã®ã¢ãŒããå¿
èŠã§ãã OSSIMã§ã¯ã
Suricataããã®åœ¹å²ãæãããŸãã
ãããè¡ãã«ã¯ã以äžã®ã¢ãã¡ãŒã·ã§ã³ã®ããã«ããã¹ãèšå®ãéãããã¹ãŠãå®è¡ããŸãã

ãã®ã»ããã¢ãããå®äºããããä»®æ³ãã·ã³ã远å ããŸãã 以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã§ã¯ã倿Žããèšå®é
ç®ã®ã¿ã



OSSIMã®å€ãã®ãµãŒãã¹ã¯ãã«ãã¹ã¬ããã¢ãŒãã§åäœãããããè€æ°ã®ã³ã¢ãã€ã³ã¹ããŒã«ããããšããå§ãããŸãã

RAMããã£ãšçœ®ãããšãæãŸããã ãã¹ãŠãã»ãŒå®å®ããŠåäœããé床ãäœäžããªãæå°ãµã€ãºã¯3GBã§ãã

1ã€ã®OSSIM管çã€ã³ã¿ãŒãã§ã€ã¹ã1ã€ã¯ãããã¯ãŒã¯IDS Suricataçšããã1ã€ã¯OpenVASçšïŒãªãã·ã§ã³ïŒã

ããã§ãä»®æ³ãã·ã³ã®æ§æãå®äºããŸããã
èšçœ®
ä»®æ³ãã·ã³ããªã³ã«ããŠã以åã«ããŠã³ããŒãããOSSIMã€ã³ã¹ããŒã«ã€ã¡ãŒãžã§ããä»®æ³ãã·ã³ã«æ¥ç¶ããŸãã

次ã«ãOSSIMãã€ã³ã¹ããŒã«ããŸãã ã€ã³ã¹ããŒã«ã¯Debianã®ã€ã³ã¹ããŒã«ãšéãã¯ãããŸãããã€ã³ã¹ããŒã«ã®ãã€ã³ãã®ã¿ãã¯ããã«å°ãããªããŸãã

ã»ããã¢ããã¯éåžžã«ç°¡åãªã®ã§ãç°¡æœã«ããããã«ãã¢ãã¡ãŒã·ã§ã³ã®ã¹ã¯ãªãŒã³ã·ã§ããã®äžéšã¯çç¥ãããŠããŸãã
ãã¹ãŠã®èšå®ãå
¥åãããšãã€ã³ã¹ããŒã«ãéå§ãããŸãã

ãcdsetupã®èµ·å...ãã¹ãããã§ãã€ã³ã¹ããŒã«ããã°ããããªãŒãºããå ŽåããããŸãã
æåŸã«ãã³ã³ãœãŒã«ã衚瀺ãããŸãïŒ

ã³ã³ãœãŒã«ã§æå®ããããªã³ã¯ã«ã¢ã¯ã»ã¹ããŠãè³æ Œæ
å ±ãå
¥åããŸãã

ããã§ã€ã³ã¹ããŒã«ã¯å®äºã§ãã
OSSIMã®æ§æ
OSSIMãæ§æããããã«ã3ã€ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãæ§æãããŸããïŒWindowsãµãŒããŒ2008 R2ãWindows 7 SP1ãUbuntu 14.04 LTSãç£èŠã«çŽæ¥æ¥ç¶ããŸãã ããã«ãDebian 6ããã»ã³ãµãŒããšããŠããªã€ã³ã¹ããŒã«ãããŠãããã¹ãã䜿çšããŠã
KismetããŒã¹ã®ã¯ã€ã€ã¬ã¹IDSã·ã¹ãã ãã»ããã¢ããããŸãã
ã»ããã¢ãããŠã£ã¶ãŒã
åã®èšå®é
ç®ã§æå®ãããè³æ Œæ
å ±ãå
¥åããŸãã

ãããŠãã»ããã¢ãããŠã£ã¶ãŒããŠã£ã³ããŠãéããŸãã

ã€ã³ã¿ãŒãã§ã€ã¹ãæ§æããŸãã

æ¬¡ã®æ®µèœã§ãOSSIMã¯ãããã¯ãŒã¯ãèªåçã«ã¹ãã£ã³ããèŠã€ãã£ãããŒãã®ã¿ã€ãã瀺ãããã«ææ¡ããŸãããã®å Žåããã¹ããã³ãã«å±ããªããã®ã¯ãã¹ãŠåé€ãããŠããŸãã

次ã®ã¹ãããã§ã¯ããã¹ã䟵å
¥æ€ç¥ã·ã¹ãã ïŒOSSECïŒãèªåçã«ã€ã³ã¹ããŒã«ã§ããŸãã Windows Serverçšã«ã€ã³ã¹ããŒã«ããŠã¿ãŸãããã è³æ Œæ
å ±ãå
¥åãããå±éããã¯ãªãã¯ããŸãã

Linuxã§åãããšãããããšã¯ãå§ãããŸããã ãã®å ŽåãOSSECã¯
ãšãŒãžã§ã³ããªãã§åäœããŸãïŒAgentlessïŒã
æ¬¡ã®æ®µéã§ã¯ããã°ã®ç£èŠãèšå®ããããã«ææ¡ãããŠããŸãããã®é
ç®ãã¹ãããããŠã察å¿ããç« ã®åŸåã«æ»ããŸãã

æåŸã®æç¹ã§ãå¿
èŠã«å¿ããŠOTXã«åå ããããææ¡ãããŸã
ãwww.alienvault.com /
my-account /
customer /
signupã§ç»é²ããããŒã¯ã³ãå
¥åããŠãã ããã


次ã«ã次ã®å
容ã®ãããã¢ãããŠã£ã³ããŠã衚瀺ãããŸãã

[Alienvault OSSIMã®æ¢çŽ¢]ãã¯ãªãã¯ãããšãæ§æãããŒãžã£ãŒãå®äºããŸãã
ã¡ãŒã«éç¥ãèšå®ãã
OSSIMã«ã¯çžé¢ã¢ã©ãŒã ã€ãã³ãã衚瀺ãããã¢ã©ãŒã ãã»ã¯ã·ã§ã³ããããŸããããã®ãããªã€ãã³ãã®éç¥ãåãåãããšã¯ã§ããŸããã ãã ããã·ã¹ãã ã«ã¯ããã±ããããšããã»ã¯ã·ã§ã³ããããåã€ãã³ãã§ã¿ã¹ã¯ãéãããšãã§ããŸãã
ãã±ããã¯å°éå®¶ãæåã§äœæããããã»ãã¥ãªãã£ã€ãã³ãïŒSIEMïŒãã°ããã®ã€ãã³ããã¢ã©ãŒã ã«ãªã£ããšãã«èªåçã«äœæã§ããŸãããã±ãããèªåçã«éãå ŽåãOSSIMã¯éç¥ãèªåçã«éä¿¡ã§ããŸãã
é»åã¡ãŒã«éç¥ã®ã»ããã¢ããã¯2段éã§è¡ãããŸããæåã«postfixãæ§æããå¿
èŠããããæ¬¡ã«éç¥ã®éä¿¡ãæå¹ã«ããŸãã
SSHãéããOSSIMã«æ¥ç¶ããŸãã

ã¢ã€ãã ãè±çã·ã¹ãã ããéžæããŠã³ã³ãœãŒã«ã«å
¥ããæ¬¡ã®ããã«å
¥åããŸãã
sed -i -e "s@mailserver_relay=no@mailserver_relay=my.corporate.mail.server@" /etc/ossim/ossim_setup.conf echo relayhost = my.corporate.mail.server:25 >> /etc/postfix/main.cf service postfix restart
泚ïŒmy.corporate.mail.serverã®ä»£ããã«ãã¡ãŒã«ãµãŒããŒãæå®ããå¿
èŠã«å¿ããŠãä»ã®postfixãã©ã¡ãŒã¿ãŒïŒæ¿èªãå®å
šãªæ¥ç¶ãªã©ïŒãæ§æããŸã-postfixã®ããã¥ã¡ã³ããåç
§ããŠãã ãããèšå®ãéãã管çã»ã¯ã·ã§ã³ã§éç¥ã®èªåéä¿¡ããªã³ã«ããŸãã

ãã®æäœã®åŸãçžé¢ã€ãã³ãã¯èªåçã«ãã±ãããäœæãã管çè
ã«éç¥ããŸãã
HIDSã»ããã¢ãã
OSSIMã®äŸµå
¥é²æ¢ã®ãã¹ãã·ã¹ãã ã¯ãæªç¥ã®
OSSECã§ã¯ãããŸããããã®æ§æã«ã€ããŠã¯ãããã«èª¬æããŸãã
HIDSãæ§æããã«ã¯ã[ç°å¢]-> [æ€åº]-> [HIDS]-> [ãšãŒãžã§ã³ã]ã«ç§»åãã2ã€ç®ã®ãã¹ãã確èªããŸãã1ã€ç®ã¯AlienVaultèªäœã2ã€ç®ã¯Windows Serverã§ãã[ã»ããã¢ãããŠã£ã¶ãŒã]ã»ã¯ã·ã§ã³ã®[HIDSã®å±é] HIDSãšãŒãžã§ã³ãã¡ãã¥ãŒã«ç§»åããŸãã

Windows 7ããã³Ubuntuã远å ããŸãã

çª
èªåã€ã³ã¹ããŒã«ã¢ãŒãã䜿çšããŠHIDSãã€ã³ã¹ããŒã«ã§ããŸã

ãŸãã¯ã宿ããexeãã¡ã€ã«ãããŠã³ããŒãããŸã

ã
èªåã¢ãŒãã§ã®ã€ã³ã¹ããŒã«ã¯ããã§ã«è¡ã£ãããšãšå€ãããŸããïŒ

exeãã¡ã€ã«ã䜿çšããŠæåã¢ãŒãã§ã€ã³ã¹ããŒã«ããå ŽåãOSSECãšãŒãžã§ã³ãã¯è¿œå ã®ãã©ã¡ãŒã¿ãŒãå
¥åããã«ã1ã¯ãªãã¯ãã§ã€ã³ã¹ããŒã«ãããŸãã

æåãããšã以äžã衚瀺ãããŸãã

Ubuntu
次ã«ãUbuntuãæ§æããSSHãä»ããŠæ¥ç¶ããOSSECãã€ã³ã¹ããŒã«ããŸãã
sudo -s apt-get install curl curl --header 'Host: www.ossec.net' --header 'User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:31.0) Gecko/20100101 Firefox/31.0' --header 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' --header 'Accept-Language: en-US,en;q=0.5' --header 'DNT: 1' --header 'Referer: http://www.ossec.net/?page_id=19' --header 'Connection: keep-alive' 'http://www.ossec.net/files/ossec-hids-2.8.tar.gz' -o 'ossec-hids-2.8.1.tar.gz' âL
泚ïŒwgetã䜿çšãããšãããŠã³ããŒãã¯æ©èœããŸããããµãŒããŒåŽã®ossec.netã§ã¯ãUser-Agentããã§ãã¯ãããŸãã tar xzf ossec-hids-2.8.1.tar.gz cd ossec-hids-2.8/ /bin/bash ./install.sh

泚ïŒ3.4ç¯ãã¢ã¯ãã£ãä¿è·ã¢ãŒãïŒIDSã®ä»£ããã«IPSïŒãæ
éã«ãªã³ã«ããŸãããã®å Žåãæ€åºã¢ãŒãã®ã¿ã䜿çšããããããyãã§ã¯ãªããnãã®ãŸãŸã«ããŸããããŒãååŸããŸãããã®ãããHIDSãšãŒãžã§ã³ãã¡ãã¥ãŒã«æ»ãã

ïŒ

ãŠãŒãã£ãªãã£/ var / ossec / bin / manage_agentsã䜿çšããŠæ§æãå®è¡ããIãæŒããŠããŒãå
¥åããçµäºïŒQïŒããŸãã

OSSECãåèµ·åããŸãã
service ossec restart
æåãããšããã¹ãã®å察åŽã«ãã¢ã¯ãã£ãããšè¡šç€ºãããŸãã

ãªã¹ãã«ãšãŒãžã§ã³ããã¢ã¯ãã£ããšããŠè¡šç€ºãããªãå Žåã¯ãOSSECãåèµ·åã§ããŸãããã®ãããSSHãä»ããŠOSSIMã«æ¥ç¶ããæ¬¡ã®ã¢ã¯ã·ã§ã³ãå®è¡ããŸãã

ããã§HIDSã®ã€ã³ã¹ããŒã«ãå®äºããçŸåšã¯[ç°å¢]-> [æ€åº]ã¿ãã§OSSECãã°ã確èªã§ããŸãã

WIDSã®ã»ããã¢ãã
次ã®ããã«WIDSãã€ã³ã¹ããŒã«ããŸãã
- Debian 6ã§ãã¹ããäœæããŸã
- æ¥ç¶ããŠWi-Fiã«ãŒããã»ããã¢ããããŸã
- Kismetãã€ã³ã¹ããŒã«ããŠæ§æãã
- OSSIM OpenVPNãµãŒããŒãã»ããã¢ãããã
- OSSIMãšDebian 6éã®éä¿¡ãæ§æãã
- rsyslogã§ãã°ã®éä¿¡ãšèšé²ãèšå®ãã
- Kismetãã©ã°ã€ã³ãæå¹ã«ãã
- KismetããXML圢åŒã®ãã°ã®å ã§ã€ã³ããŒããèšå®ããŸããã
- OSSIMã«æ°ããã»ã³ãµãŒã远å ããŸã
- ãœãªã¥ãŒã·ã§ã³ã®å¥å
šæ§ãæ€èšŒãã
ä»®æ³ãã·ã³ã®ã»ããã¢ãã
ã¯ã€ã€ã¬ã¹IDSã·ã¹ãã ãã€ã³ã¹ããŒã«ããã«ã¯ãDebian 6ãããªã€ã³ã¹ããŒã«ããããã¹ããå¿
èŠã§ãã
ESXiã§æ°ããä»®æ³ãã·ã³ãäœæããããã«USBã³ã³ãããŒã©ãŒãšUSB Wi-Fiã«ãŒãã远å ããŸãã

ãã®äŸã§ã¯ãTOTOLink N500UD USB Wi-Fiã«ãŒãã䜿çšããŸãã
Debianã®ã€ã³ã¹ããŒã«ãšæ§æ
Debian 6ã®ã€ã³ã¹ããŒã«ã ãã¹ãŠã®èšå®ã¯ããªãã®è£éã§ãããDebianã®ã€ã³ã¹ããŒã«ã¯æšæºã§ããããããã®ããã¥ã¢ã«ã§ã¯çç¥ãããŠããŸãã
OSãã€ã³ã¹ããŒã«ããããSSHã«æ¥ç¶ããŠ
ãããã¯ãŒã¯ã«ãŒããã©ã€ããŒãã€ã³ã¹ããŒã«ã
ãŸã ã
wget http://totolink.ru/files/soft/N500UD_Linux_V2.6.1.3.zip apt-get install unzip unzip N500UD_Linux_V2.6.1.3.zip apt-get install build-essential apt-get install linux-headers-$(uname -r) make make install aptitude install wireless-tools apt-get install ssh openvpn kismet ntp reboot
ãã®åŸãiwconfigã§æ°ããã€ã³ã¿ãŒãã§ã€ã¹ã確èªããŸãã

DebianããOSSIMãžã®ãã°ã®éä¿¡ãèšå®ããŸãã
echo "*.* @10.67.68.1" > /etc/rsyslog.d/wids_alienvault.conf
IPã¢ãã¬ã¹ã倿Žããªãã§ãã ãããããã¯ãã®ããã«ããå¿
èŠããããŸãã ããã¯OpenVPNãµãŒããŒã®IPã¢ãã¬ã¹ã§ããããã®åŸOSSIMã§çºçããŸãã
次ã«
ãæ¬¡ã®å
容ã§ã¹ã¯ãªãã
/etc/init.d/wids_alienvault.shãäœæããŸãã
圌ã«èµ°ãæš©å©ãäžããïŒ
chmod 755 /etc/init.d/wids_alienvault.sh
ãããŠãçµäº0ãŸã§/etc/rc.localã®èµ·åã«æžã蟌ã¿ãŸãïŒ

次ã«ãKismetãæ§æããŸãã
ãã¡ã€ã«
/etc/kismet/kismet.confãŸããã¢ããã¿ãŒãæ§æããŸãã
source=rt2500,ra0,ra0-wids
ãããã»ããã®ååã¯ã次ã®ã³ãã³ãã§è¡šç€ºã§ããŸãã
lsmod | grep ^usbcore
XMLã¬ããŒããäœæããæéãèšå®ããŸãã
logexpiry=3600
äœæããããã°ã®ååãæ§æããŠãOSSIMãã€ã³ããŒãããã³ã¯ãªãŒã³ã¢ãããããã¡ã€ã«ãæ£ããæ±ºå®ããããã«ããŸãã
logdefault=10.67.68.10 logtemplate=/var/log/kismet/%n_%D-%i.%l
åèµ·ååŸïŒ
reboot
OpenVPNãæ§æãã
SSHçµç±ã§OSSIMã«æ¥ç¶ãããè±çã·ã¹ãã ãé
ç®ãéžæããŠãã³ãã³ããå
¥åããŸãã
alienvault-reconfig --add_vpnnode=WIDS-Sensor
Debianã«æ»ããèšå®æžã¿ã®OpenVPNã¢ãŒã«ã€ããèšå®ãšãšãã«ã³ããŒããŸãã
scp root@10.1.193.123:/etc/openvpn/nodes/WIDS-Sensor.tar.gz ~
æ§æãé©çšããŸãã
tar xzf WIDS-Sensor.tar.gz rm -f WIDS-Sensor.tar.gz mv * /etc/openvpn/
OpenVPNã確èªããŸãã
/etc/init.d/openvpn restart Ifconfig tun0

Kismetã®ã»ããã¢ãã
OSSIMã«æ»ããŸãã
rsyslogãã»ããã¢ããããŸãã
echo if \$programname contains \'ismet\' then /var/log/kismet.log >> /etc/rsyslog.d/kismet.conf echo \& \~ >> /etc/rsyslog.d/kismet.conf service rsyslog restart
ãã©ã°ã€ã³ããã°ãååŸãããã¡ã€ã«ãžã®ãã¹ã倿ŽããŸãã
sed âi âe "s@/var/log/syslog@/var/log/kismet.log@" /etc/ossim/agent/plugins/kismet.cfg
次ã«ãKismetãã°ãåŠçãããã©ã°ã€ã³ãæå¹ã«ããŸãããã®ããã«ãexitã³ãã³ãã䜿çšããŠOSSIMã¡ãã¥ãŒãçµäºãããã©ã°ã€ã³ãæå¹ã«ããŸãã

ãã¹ãŠãæ£ããè¡ããããšããåæ->ã»ãã¥ãªãã£ã€ãã³ãïŒSIEMïŒãã®ãã°ã衚瀺ãããŸãã

XMLãã°ã®ã€ã³ããŒãã®ã»ããã¢ãã
ããã§ãDebianããã®XML圢åŒã®ãã°ã®ã€ã³ããŒããèšå®ããããšãã§ããŸãã
ããã¯ãOSSIMãã¢ã©ãŒãã ãã§ãªããWi-Fiã¯ã©ã€ã¢ã³ãããã³ãããã¯ãŒã¯ã«é¢ããå©çšå¯èœãªãã¹ãŠã®ããŒã¿ãè¿æ¥ã§åä¿¡ã§ããããã«ããããã«å¿
èŠã§ããããã¯ãç°å¢->æ€åº->ã¯ã€ã€ã¬ã¹IDSã«åæ ãããŸãã
ãã¹ã¯ãŒããªãã§SSHèªèšŒãèšå®ããŠãXMLã¬ããŒããåä¿¡ããã»ã³ãµãŒããã¬ããŒããåé€ããã¹ã¯ãªãããæ£ããæ©èœããããã«ããŸãããã
OSSIMã§ã次ãå®è¡ããŸãã
ssh-keygen ssh-copy-id root@10.67.68.10

ãã
ã§ã次ã®å
容ã®ãã¡ã€ã«
/etc/cron.hourly/kismetãäœæããŸãã
ã¹ã¯ãªããèªäœãã³ããŒããŸãã
cp /usr/share/ossim/www/wireless/kismet_sites.pl /var/ossim/kismet/kismet_sites.pl
ãããŠãã®äžã®ã¢ãã¬ã¹ãä¿®æ£ããŸãïŒ
echo \$sites{\'10.67.68.10\'}=\'/var/log/kismet\'\; >> /var/ossim/kismet/kismet_sites.pl
ã»ã³ãµãŒã®ã»ããã¢ãã
次ã«ãWebã€ã³ã¿ãŒãã§ãŒã¹ã«ç§»åããŸãã

æ°ããã»ã³ãµãŒã远å ããŸãã

ã»ã³ãµãŒã®ã¹ããŒã¿ã¹ã¯æ¬¡ã®ããã«èµ€ãååã«ãªããŸãã

次ã«ã[ç°å¢]-> [æ€åº]-> [ã¯ã€ã€ã¬ã¹IDS]ã«ç§»åããå Žæãšã»ã³ãµãŒã远å ããŸãã




ã³ãã³ããå®è¡ããåŸïŒ
/usr/bin/perl /usr/share/ossim/www/wireless/fetch_kismet.pl
ãããŠãæåããå Žåãæ¬¡ã®ããã«ãªããŸãã

ãã®ã¢ã¯ã·ã§ã³ã®åŸã[ç°å¢]-> [æ€åº]-> [ã¯ã€ã€ã¬ã¹IDS]ã¢ã€ãã ã«ããŒã¿ã衚瀺ãããŸãã

ã·ã¹ãã ãã°åéãæ§æãã
VMware ESXiãWindowsãµãŒããŒãããã³Ubuntuã§ãã°åéãã»ããã¢ããããŸãã
ãã°ãåéããã«ã¯ã次ã®ã¢ã¯ã·ã§ã³ãå®è¡ããå¿
èŠããããŸãã
- OSSIMã®ãã¹ãããã®ãã°éä¿¡ã®æ§æ
- OSSIMã€ãã³ãåŠçãã©ã°ã€ã³ããã°ãèªã¿åããã¡ã€ã«ã確èªãã
- rsyslogæ§æãä»ããŠããã¹ãããåå¥ã®ãã¡ã€ã«ãžã®ãã®ã³ã°ãæ§æããŸã
- ãã©ã°ã€ã³ãæå¹ã«ãã
- æäœæ§ã確èªãã
VMware
æåã«ãESXiãžã®ãã°ã®éä¿¡ãæ§æããŸããããã®ããã«ã詳现èšå®ãéããŸãã

UDPãä»ãããã°ã®éä¿¡ãæå¹ã«ããŸãã

ãã®åŸãESXiãã©ã°ã€ã³ããã°ãååŸããå Žæã確èªããŸãã
cat /etc/ossim/agent/plugins/vmware-esxi.cfg | grep location

rsyslogãã»ããã¢ããããŸãã
echo if \$fromhost-ip == \'10.1.193.76\' then -/var/log/vmware-esxi.log >> /etc/rsyslog.d/esxi.conf service rsyslog restart
ãã©ã°ã€ã³ãæå¹ã«ããSSHãä»ããŠOSSIMã«æ¥ç¶ããŸãã

[åæ]-> [ã»ãã¥ãªãã£ã€ãã³ãïŒSIEMïŒ]ãéããæ¬¡ã確èªããŸãã

WindowsãµãŒããŒ
Windowsãããã°ãéä¿¡ããã«ã¯ãã·ã¹ãã ãã°ãsyslog圢åŒã§éä¿¡ã§ãã
Snareããã°ã©ã ãå¿
èŠã§ãã
ããŠã³ããŒãããŠå®è¡ïŒ

Webã¢ã¯ã»ã¹ãæå¹ã«ããŸãã

ã€ã³ã¹ããŒã«ãå®äºããŸãã

ãã©ãŠã¶ãŒã§ã¢ãã¬ã¹ãéããŸãïŒ
localhost ïŒ6161
ã¹ãã¢ãã°ã€ã³ãã€ã³ã¹ããŒã«äžã«æå®ããããã¹ã¯ãŒããå
¥åããããããã¯ãŒã¯æ§æãã«ç§»åããŠä»¥äžãæå®ããŸãã


èšå®ãä¿åããããã³ã³ãœãŒã«ãéããŠã¹ãã¢ãåèµ·åããŸãã
net stop snare net start snare

ãã©ã°ã€ã³ããã°ãååŸããå Žæã確èªããŸãã
cat /etc/ossim/agent/plugins/snare.cfg | grep location

rsyslogãæ§æããŸãã rsyslogèšå®ã«ã¯ãäºåã«å®çŸ©ãããã¹ãã¢èšå®ïŒzzzzz_snare.confïŒãæ¢ã«ãããŸããããã¯
ãOSSIMãã©ãŒã©ã ã®ã¬ã€ã
ã«åŸã£ãŠ 1ã€ã®ãã©ã¡ãŒã¿ãŒã®ã¿ã眮ãæããŠãå°ãä¿®æ£ããŸãã
sed -i -e "s@msg@rawmsg@" /etc/rsyslog.d/zzzzz_snare.conf service rsyslog restart
次ã«ããã©ã°ã€ã³èªäœãéžæããããšãé€ããŠã
VMwareã®ã»ããã¢ãããšåæ§ã«ãã©ã°ã€ã³ãæ§æããŸãã

åèµ·ååŸã[åæ]-> [ã»ãã¥ãªãã£ã€ãã³ãïŒSIEMïŒ]ããã§ãã¯ã€ã³ããŸãã

Ubuntu
Ubuntuãæ§æããã«ã¯ãrsyslogã䜿çšããŸãã SSHãä»ããŠUbuntuã«æ¥ç¶ããOSSIMãžã®ãã°éä¿¡ãèšå®ããŸãã
echo *.* @10.1.193.123 > /etc/rsyslog.d/alienvault.conf service rsyslog restart
ãã©ã°ã€ã³ããã°ãååŸããå Žæã確èªããŸãã

cat /etc/ossim/agent/plugins/syslog.cfg
ãã°ãã¡ã€ã«ãžã®ãã¹ã倿ŽããŸãã
sed âi âe "s@/var/log/syslog@/var/log/ubuntusyslog.log@" /etc/ossim/agent/plugins/syslog.cfg
次ã«ãOSSIMã§rsyslogãæ§æããŸãã
echo if \$fromhost-ip == \'10.1.193.77\' then -/var/log/ubuntusyslog.log >> /etc/rsyslog.d/ubuntu.conf service rsyslog restart
åã®æ®µèœãšåæ§ã«ãå¿
èŠãªãã©ã°ã€ã³ãéžæãããã©ã°ã€ã³ã®ãªã¹ãã§ã®ã¿ãã©ã°ã€ã³ããªã³ã«ããŸãã

é©çšããã³æ€èšŒïŒ

ãæ³šæ
ã倿Žãé©çšããéžæããåŸããAlienVault ReconfigããŠã£ã³ããŠã衚瀺ãããªãå Žå

OSSIMãåèµ·åããŸãïŒææ°ããŒãžã§ã³4.15.2ã§ã¯ããã®ãããªãã°ã宿çã«è¡šç€ºãããŸãïŒ
cp1251ïŒããªã«æåïŒã§ãšã³ã³ãŒãããããã°ã®è§£æã«é¢ããåé¡ã解決ããã«ã¯ã以äžãå®è¡ããå¿
èŠããããŸãã
ãã¡ã€ã«
/usr/share/alienvault/ossim-agent/ParserDatabase.pyã® 288è¡ç®ä»¥éïŒ
if len(ret) > 0:
貌ãä»ãïŒ
e=list(e) x=[x.decode('cp1251').encode('utf8') if isinstance(x, basestring) else x for x in e]
次ã®è¡ã®163è¡ç®ã®
/usr/share/alienvault/ossim-agent/TailFollowBookmark.pyãã¡ã€ã«ã§ïŒ
def _open_file(self, fromrotate=False): """ Opens the file and seeks to the specified position based on the keyword arguments: offset and whence. Furthermore, the _current_file attribute is set as a side-effect. fromrotate: Indicates if the file is opened when a log rotation is detected """
貌ãä»ãïŒ
if «alerts.log» in self.filename: self.encode='cp1251' else: self.encode='utf8'
ãšã³ã³ãŒãã£ã³ã°ã®åé¡ã«é¢ããè°è«ãè¡ãã
ããã©ãŒã©ã ãžã®ãªã³ã¯ ã
ãã®ãã°ã解決ããããã®æ
å ±ãããããšãããããŸããã
ArcSightçµ±å
次ã«ãOSSIMãšArcemight SIEMã·ã¹ãã ã®çµ±åãèšå®ããŠã¿ãŸãããã
ãã®ãããªãã³ãã«ã¯ãæ¬ç€Ÿã«å ããŠãä¿è·ããã³ç£èŠããå¿
èŠã®ããæ°åã®å°ããªæ¯åºãããå ŽåãArcSightã©ã€ã»ã³ã¹ã§æ°åäžãç¯çŽã§ããŸãã
ãã®ã»ã¯ã·ã§ã³ã®ç®çã¯ãArcSightåŽã§ãã°ãçžé¢ãããã®ã§ã¯ãªããArcSightã«ãã£ãŠOSSIMã«ãã§ã«çžé¢ãããŠãããã°ãéä¿¡ããŠãè² è·ãå¢ããããšã§ãã
ãããè¡ãã«ã¯ãã³ãã¯ã¿ïŒSyslogã³ãã¯ã¿ã¿ã€ãïŒãã€ã³ã¹ããŒã«ããæ¬¡ã®FlexAgentã远å ããŸãã
ã³ãã¯ã¿ãã©ã«ããŒãžãããã«ã
ãŠãŒã¶ãŒ\ãšãŒãžã§ã³ã\ flexagent \ syslog ããžã ãã¡ã€ã«ådo "
ossim.sdkrfilereader.properties "
agent.propertiesãã¡ã€ã«ã§ãè¡ãšãŒãžã§ã³ã[0] .customsubagentlistã倿ŽããŠãossimãã远å ããŸããæ¬¡ã«äŸã瀺ããŸãã
ãšãŒãžã§ã³ã[0] .customsubagentlist = ossim | ciscopix_syslog | netscreen_syslog | ...
ãããŠããšãŒãžã§ã³ããã©ã€ã³[0] .usecustomsubagentlistã§trueã«èšå®ããŸãã
次ã«ãOSSIMèšå®ã«ç§»åããŸãã

ãŸããsyslogã§ã¢ã©ãŒã ã®éä¿¡ãæå¹ã«ããŸãã

ãã°ãrsyslog OSSIMã«éä¿¡ããããã«èšå®ããåŸã
/etc/rsyslog.confãã¡ã€ã«ã«æ¬¡ã®è¡ã远å ããŸãã
*ã* ip.your.Flex.agent

ãã®åŸãè§£ææžã¿ã®çžé¢ãã°ãArcSightã³ãã¯ã¿ã«è¡šç€ºãããŸãã

䜿çšãããœãŒã¹