1 of 93

SYSSEC2 - IDS

Justin David Pineda

2 of 93

Agenda for today

  • Limitations of a firewall
  • Technical Detective Controls
  • Exercise 5: Setting up Snort IDS

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

2

3 of 93

LIMITATIONS OF TECHNICAL PREVENTIVE CONTROLS

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

3

4 of 93

Firewalls

  • Allow and deny traffic.
  • Very limited actions.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

4

5 of 93

Limitations of a firewall

  • If policy states allow, the firewall will permit traffic.
  • It cannot check whether the communication is legit or not.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

5

6 of 93

Limitations of a firewall

  • Firewall allows web traffic.
  • Firewall cannot control what the user inputs in the web traffic.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

6

7 of 93

Limitations of a firewall

  • Firewall allows web traffic.
  • Firewall cannot control what the user inputs in the web traffic.
  • In this case, the website is vulnerable to Cross Site Scripting.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

7

8 of 93

Limitations of a firewall

  • Firewall allows web traffic.
  • Firewall cannot control what errors the web site is forced to show.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

8

9 of 93

Limitations of a firewall

  • Firewall allows web traffic.
  • Firewall cannot control what errors the web site is forced to show.
  • In this case, the website is vulnerable to SQL Injection.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

9

10 of 93

TECHNICAL DETECTIVE CONTROLS

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

10

Excerpts from: Intrusion Detection Systems with Snort by Bruce Perens

11 of 93

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

11

Protection = Prevention + Detection + Response

12 of 93

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

12

The specific technical detective controls have been discussed in Day 1: Infrastructure Security.

13 of 93

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

13

We will focus on:

Intrusion Detection Systems (IDS)

14 of 93

Intrusion Detection

  • A set of techniques and methods that are used to detect suspicious activity
  • Network and host level
    • Intruders have signatures, like computer viruses.
    • Anomaly-based intrusion detection usually depends on packet anomalies present in protocol header parts

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

14

15 of 93

Snort

  • Rules stored in text files that can be modified by a text editor.
  • Grouped in categories.
  • Reads these rules at the start-up time and builds internal data structures or chains to apply these rules to captured data.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

15

16 of 93

Network IDS (NIDS)

  • NIDS are intrusion detection systems that capture data packets traveling on the network media (cables, wireless) and match them to a database of signatures.
  • Snort is a NIDS.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

16

17 of 93

Host IDS (HIDS)

  • Installed as agents on a host.
  • Can look into system and application log files to detect any intruder activity.
    • Reactive: They inform you only when something has happened.
    • Proactive: Sniff the network traffic coming to a particular host on which the HIDS is installed and alert you in real time.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

17

18 of 93

Signatures

  • Pattern that you look for inside a data packet.
  • Used to detect one or multiple types of attacks.
  • Can be found in:
    • IP header
    • Transport layer header (TCP or UDP header)
    • Application layer header or payload

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

18

19 of 93

Alerts

  • Any sort of user notification of an intruder activity.
  • Pop-up windows, logging to a console, sending e-mail

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

19

20 of 93

Logs

  • Usually saved in file.
  • By default Snort saves these messages under \log directory

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

20

21 of 93

False Alarms/ False Positives

  • Alerts generated due to an indication that is not an intruder activity.
  • For example, misconfigured internal hosts may sometimes broadcast messages that trigger a rule resulting in generation of a false alert.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

21

22 of 93

Sensor

  • The machine on which an intrusion detection system is running.
  • It is used to “sense” the network

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

22

23 of 93

IDS Topology

  • Best practice: Multiple instances of the IDS in the network.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

23

24 of 93

IDS Policy

  • A policy to detect intruders and take action when you find such activity.
  • A policy must dictate IDS rules and how they will be applied.
    • Who will monitor the IDS?
    • Who will administer the IDS, rotate logs and so on?
    • Who will handle incidents and how?
    • What will be the escalation process (level 1, level 2 and so on)?
    • Reporting
    • Signature updates
    • Documentation

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

24

25 of 93

Components of Snort

  • Packet Decoder
  • Preprocessors
  • Detection Engine
  • Logging and Alerting System
  • Output Modules

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

25

26 of 93

Components of Snort

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

26

27 of 93

Components of Snort

  • The packet decoder takes packets from different types of network interfaces and prepares the packets to be preprocessed or to be sent to the detection engine.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

27

  • Packet Decoder
  • Preprocessors
  • Detection Engine
  • Logging and Alerting System
  • Output Modules

28 of 93

Components of Snort

  • Preprocessors are components or plug-ins that can be used with Snort to arrange or modify data packets before the detection engine does some operation to find out if the packet is being used by an intruder.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

28

  • Packet Decoder
  • Preprocessors
  • Detection Engine
  • Logging and Alerting System
  • Output Modules

29 of 93

Components of Snort

  • Most important part of Snort. Its responsibility is to
  • Detect if any intrusion activity exists in a packet.
  • Rules are read into internal data structures or chains where hey are matched against all packets.
  • If a packet matches any rule, appropriate action is taken; otherwise the packet is dropped.
  • Appropriate actions may be logging the packet or generating alerts.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

29

  • Packet Decoder
  • Preprocessors
  • Detection Engine
  • Logging and Alerting System
  • Output Modules

30 of 93

Components of Snort

  • Depending upon what the detection engine finds inside a packet, the packet may be used to log the activity or generate an alert.
  • Logs are kept in simple text files, tcpdump-style files or some other form.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

30

  • Packet Decoder
  • Preprocessors
  • Detection Engine
  • Logging and Alerting System
  • Output Modules

31 of 93

Components of Snort

  • Output modules or plug-ins can do different operations depending on how you want to save output generated by the logging and alerting system of Snort.
  • Basically these modules control the type of output generated by the logging and alerting system.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

31

  • Packet Decoder
  • Preprocessors
  • Detection Engine
  • Logging and Alerting System
  • Output Modules

32 of 93

Summary

  • Packet Decoder - Prepares packets for processing.
  • Preprocessors or Input Plugins - Used to normalize protocol headers, detect anomalies, packet reassembly and TCP stream re-assembly.
  • Detection Engine - Applies rules to packets.
  • Logging and Alerting System - Generates alert and log messages.
  • Output Modules - Process alerts and logs and generate final output.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

32

33 of 93

Dealing with Switches

  • Allows you to replicate all ports traffic on one port where you can attach the Snort machine. (spanning ports)
  • Best way to install Snort is right behind the firewall or router so that all of the Internet traffic is visible to Snort before it enters any switch or hub

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

33

34 of 93

Company Topology

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

34

35 of 93

IDS in a Switch

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

35

36 of 93

IDS in a Hub

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

36

37 of 93

Working with Snort Rules

  • snort.conf
  • alert ip any any -> any any (msg: "IP Packet detected";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

37

38 of 93

Test rule

  • alert ip any any -> any any (msg: "IP Packet detected";)
    • Bad! Because it will detect anything
    • Good! Because it will tell you that Snort is working fine.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

38

39 of 93

Test rule

  • alert ip any any -> any any (msg: "IP Packet detected";)

.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

39

Type of message

40 of 93

Test rule

  • alert ip any any -> any any (msg: "IP Packet detected";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

40

Protocol

41 of 93

Test rule

  • alert ip any any -> any any (msg: "IP Packet detected";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

41

Source IP

42 of 93

Test rule

  • alert ip any any -> any any (msg: "IP Packet detected";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

42

Source Port

43 of 93

Test rule

  • alert ip any any -> any any (msg: "IP Packet detected";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

43

Direction of traffic

44 of 93

Test rule

  • alert ip any any -> any any (msg: "IP Packet detected";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

44

Target IP

45 of 93

Test rule

  • alert ip any any -> any any (msg: "IP Packet detected";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

45

Target Port

46 of 93

Test rule

  • alert ip any any -> any any (msg: "IP Packet detected";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

46

Message that will be logged.

47 of 93

Sample ICMP Rule

  • alert icmp any any -> any any (msg: "ICMP Packet found";)
    • Noisy!
    • Checks if the connection is working.
    • Heartbeat check.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

47

48 of 93

Structure of a Rule

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

48

Rule Header

Rule Options

49 of 93

Structure of a Rule

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

49

Rule Header

Rule Options

  • Contains information about what action a rule takes.
  • Criteria

50 of 93

Structure of a Rule

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

50

Rule Header

Rule Options

  • Alert message and information about which part of the packet should be used to generate the alert message.
  • Provides additional criteria.

51 of 93

Structure of a Snort Rule Header

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

51

Action

Protocol

Address

Port

Direction

Address

Port

52 of 93

ICMP Rule Specified

  • alert icmp any any -> any any (msg: "Ping with TTL=100"; \ttl: 100;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

52

53 of 93

Rule Actions

  • Pass – Ignore the packet
  • Log – Log the packet
  • Alert – Send an alert message when condition is met.
  • Activate – Create an alert and activate another rule.
  • Dynamic – Invoked when a rule is “activated”
  • User Defined Actions – Custom action

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

53

54 of 93

Alert Exclusion

  • alert icmp ![192.168.2.0/24] any -> any any \ (msg: "Ping with TTL=100"; ttl: 100;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

54

55 of 93

Port Ranges

  • alert udp any 1024:2048 -> any any (msg: “UDP ports”;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

55

56 of 93

Exploring TCP/IP Ports

  • Well-known ports are most common in daily operations and range from 1 to 1024.
  • Registered ports range from 1025 to 49151. Registered ports are those that have been identified as usable by other applications running outside of the user’s present purview.
  • Dynamic ports range from 49152 to 65535. These are the free ports that are available for any TCP or UDP request made by an application.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

56

57 of 93

Direction

  • -> - left to right
  • <- - right to left
  • <> - bi-directional

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

57

58 of 93

Rule Options

  • May be one option or many and the options are separated with a semicolon.
  • Multiple options form a logical AND.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

58

59 of 93

ACK keyword

  • alert tcp any any -> 192.168.1.0/24 any (flags: A; \ack: 0; msg: "TCP ping detected";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

59

60 of 93

The content keyword

  • alert tcp 192.168.1.0/24 any -> ![192.168.1.0/24] any \(content: "GET"; msg: "GET matched";)
  • alert tcp 192.168.1.0/24 any -> ![192.168.1.0/24] any \(content: "|47 45 54|"; msg: "GET matched";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

60

61 of 93

The content-list keyword

  • alert ip any any -> 192.168.1.0/24 any (content-list: \"porn"; msg: "Porn word matched";)
  • File name: porn
    • “porn”
    • “hardcore”
    • “under 18”

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

61

62 of 93

TCP Flags

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

62

63 of 93

TCP Flags

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

63

64 of 93

SYN FIN Packets Detected

  • alert tcp any any -> 192.168.1.0/24 any (flags: SF; \msg: “SYNC-FIN packet detected”;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

64

65 of 93

The itype keyword

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

65

66 of 93

The itype keyword

  • alert icmp any any -> any any (itype: 4; \msg: "ICMP Source Quench Message received";)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

66

67 of 93

The msg keyword

  • Used to add a text string to logs and alerts.
  • Add a message inside double quotations after this keyword
  • msg: "Your message text here";

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

67

68 of 93

The nocase keyword

  • No arguments.
  • Make a case insensitive search of a pattern within the data part of a packet.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

68

69 of 93

The priority keyword

  • Assigns a priority to a rule.
  • A number argument to this keyword.
  • Number 1 is the highest priority
  • alert ip any any -> any any (ipopts: lsrr; \msg: "Loose source routing attempt"; priority: 10;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

69

70 of 93

The react keyword

  • Keyword is used with a rule to terminate a session to block some sites or services
  • Sends a TCP FIN and/or FIN packet to both sending and receiving hosts every time it detects a packet that matches these criteria.
  • The rule causes a connection to be closed.
  • alert tcp 192.168.1.0/24 any -> any 80 (msg: "Outgoing \HTTP connection"; react: block;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

70

71 of 93

The react keyword

  • Keyword is used with a rule to terminate a session to block some sites or services
  • Sends a TCP FIN and/or FIN packet to both sending and receiving hosts every time it detects a packet that matches these criteria.
  • Can also use the warn modifier to send a visual notice to the source.
  • alert tcp 192.168.1.0/24 any -> any 80 (msg: "Outgoing \HTTP connection”; react: warn, msg;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

71

72 of 93

The reference keyword

  • Add a reference to information present on other systems available on the Internet.
  • Does not play any role in the detection mechanism itself.
  • Usual references: CVE and Bugtraq.
  • alert udp $EXTERNAL_NET any -> $HOME_NET 1900 \ (msg:"MISC UPNP malformed advertisement"; \content:"NOTIFY * "; nocase; classtype:misc-attack; \ reference:cve,CAN-2001-0876; reference:cve, \CAN-2001-0877; sid:1384; rev:2;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

72

73 of 93

The resp keyword

  • Used to knock down hacker activity by sending response packets to the host that originates a packet matching the rule.
  • alert tcp any any -> 192.168.1.0/24 8080 (resp: rst_snd;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

73

74 of 93

The resp keyword

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

74

75 of 93

The sameip keyword

  • Used to check if source and destination IP addresses are the same in an IP packet.
  • Has no arguments.
  • alert ip any any -> 192.168.1.0/24 any (msg: "Same IP"; \sameip;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

75

76 of 93

The seq keyword

  • Used to test the sequence number of a TCP packet.
  • seq: "sequence_number";

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

76

77 of 93

The session keyword

  • Used to dump all data from a TCP session.
  • Can dump all session data or just printable characters.
  • log tcp any any -> 192.168.1.0/24 110 (session: printable;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

77

78 of 93

The sid keyword

  • Used to add a “Snort ID” to rules.
  • Output modules or log scanners can use SID to identify rules.
    • Range 0-99 is reserved for future use.
    • Range 100-1,000,000 is reserved for rules that come with Snort distribution.
    • All numbers above 1,000,000 can be used for local rules.
  • alert ip any any -> any any (ipopts: lsrr; \msg: "Loose source routing attempt"; sid: 1000001;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

78

79 of 93

The tag keyword

  • Can be used for logging additional data from/to the intruder host when a rule is triggered.
  • Data can then be analyzed later on for detailed intruder activity.
  • tag: <type>, <count>, <metric>, [direction]

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

79

80 of 93

The tag keyword

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

80

81 of 93

Writing Good Rules

  • A message part using the msg keyword.
  • Rule classification, using the classification keyword.
  • Use a number to identify a rule with the help of the sid keyword.
  • If the vulnerability is known, always use a reference to a URL where more information can be found using the reference keyword.
  • Always use the rev keyword in rules to keep a record of different rule versions.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

81

82 of 93

EXERCISE 5: SETTINGUP SNORT IDS

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

82

83 of 93

Objectives

  • Install and configure Snort.
  • Test if Snort is working correctly.
  • Create basic signature-based rules.
  • Create basic anomaly-based rules.
  • Test the rules created.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

83

84 of 93

1. Go to the Command Prompt and Run as Admin

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

84

85 of 93

2. Go to the C:\Snort\etc directory. Open the snort conf file

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

85

86 of 93

3. On the Command Prompt, go to the C:\Snort\bin.

  • Type the following: snort -W

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

86

87 of 93

4. Test the connection. �Type: snort -i 2 -c c:\Snort\etc\snort.conf -T

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

87

88 of 93

5. Run Snort as an IDS. �Type: snort -i 2 -c c:\Snort\etc\snort.conf -A console

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

88

89 of 93

6. Output Snort logs to Syslog. �Type: snort -i 2 -c c:\Snort\etc\snort.conf -s

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

89

90 of 93

7. Try adding rules. Go to C:\Snort\rules directory. Open local.rules file in Notepad

  • Add the following:
    • alert icmp any any -> any any (msg:"ICMP Testing Rule"; sid:100001;)
    • alert udp any any -> any any (msg:"UDP Testing Rule"; sid:100002;)
    • alert tcp any any -> any any (msg:"TCP Testing Rule"; sid:100003;)

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

90

91 of 93

7. Try adding rules. Go to C:\Snort\rules directory. Open local.rules file in Notepad

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

91

92 of 93

Tasks:

  • Create a rule that will detect:
    • An outbound web connection.
    • A Telnet connection.
    • A X-mas Scan.
    • A string with the keywords “INSERT” “SELECT” and “DELETE”

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

92

93 of 93

Deliverables:

  • Powerpoint slides in PDF format containing:
    • Local.rules file contents
    • Logs in the Syslog server showing rules have been implemented
  • Filename: COMSEC2_Exercise5.pkt
  • Subject: COMSEC2 – Exercise 5 – Last Names of the Members
  • Make sure all rules are configured properly.
  • 2 groups to present their solution.

COMSEC2 – Justin David Pineda - © All Rights Reserved 2016

93