SYSSEC2 - IDS
Justin David Pineda
Agenda for today
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
2
LIMITATIONS OF TECHNICAL PREVENTIVE CONTROLS
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
3
Firewalls
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
4
Limitations of a firewall
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
5
Limitations of a firewall
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
6
Limitations of a firewall
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
7
Limitations of a firewall
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
8
Limitations of a firewall
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
9
TECHNICAL DETECTIVE CONTROLS
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
10
Excerpts from: Intrusion Detection Systems with Snort by Bruce Perens
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
11
Protection = Prevention + Detection + Response
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
12
The specific technical detective controls have been discussed in Day 1: Infrastructure Security.
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
13
We will focus on:
Intrusion Detection Systems (IDS)
Intrusion Detection
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
14
Snort
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
15
Network IDS (NIDS)
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
16
Host IDS (HIDS)
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
17
Signatures
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
18
Alerts
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
19
Logs
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
20
False Alarms/ False Positives
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
21
Sensor
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
22
IDS Topology
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
23
IDS Policy
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
24
Components of Snort
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
25
Components of Snort
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
26
Components of Snort
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
27
Components of Snort
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
28
Components of Snort
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
29
Components of Snort
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
30
Components of Snort
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
31
Summary
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
32
Dealing with Switches
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
33
Company Topology
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
34
IDS in a Switch
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
35
IDS in a Hub
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
36
Working with Snort Rules
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
37
Test rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
38
Test rule
.
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
39
Type of message
Test rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
40
Protocol
Test rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
41
Source IP
Test rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
42
Source Port
Test rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
43
Direction of traffic
Test rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
44
Target IP
Test rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
45
Target Port
Test rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
46
Message that will be logged.
Sample ICMP Rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
47
Structure of a Rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
48
Rule Header | Rule Options |
Structure of a Rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
49
Rule Header | Rule Options |
Structure of a Rule
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
50
Rule Header | Rule Options |
Structure of a Snort Rule Header
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
51
Action | Protocol | Address | Port | Direction | Address | Port |
ICMP Rule Specified
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
52
Rule Actions
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
53
Alert Exclusion
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
54
Port Ranges
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
55
Exploring TCP/IP Ports
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
56
Direction
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
57
Rule Options
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
58
ACK keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
59
The content keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
60
The content-list keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
61
TCP Flags
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
62
TCP Flags
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
63
SYN FIN Packets Detected
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
64
The itype keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
65
The itype keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
66
The msg keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
67
The nocase keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
68
The priority keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
69
The react keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
70
The react keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
71
The reference keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
72
The resp keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
73
The resp keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
74
The sameip keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
75
The seq keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
76
The session keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
77
The sid keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
78
The tag keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
79
The tag keyword
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
80
Writing Good Rules
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
81
EXERCISE 5: SETTINGUP SNORT IDS
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
82
Objectives
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
83
1. Go to the Command Prompt and Run as Admin
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
84
2. Go to the C:\Snort\etc directory. Open the snort conf file
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
85
3. On the Command Prompt, go to the C:\Snort\bin.
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
86
4. Test the connection. �Type: snort -i 2 -c c:\Snort\etc\snort.conf -T
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
87
5. Run Snort as an IDS. �Type: snort -i 2 -c c:\Snort\etc\snort.conf -A console
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
88
6. Output Snort logs to Syslog. �Type: snort -i 2 -c c:\Snort\etc\snort.conf -s
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
89
7. Try adding rules. Go to C:\Snort\rules directory. Open local.rules file in Notepad
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
90
7. Try adding rules. Go to C:\Snort\rules directory. Open local.rules file in Notepad
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
91
Tasks:
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
92
Deliverables:
COMSEC2 – Justin David Pineda - © All Rights Reserved 2016
93