By: Paul Albert
Project Description Design Protocols User Profiles Deliverables Timeline Budget Demonstration Conclusion
This project creates an easy-to-implement, accurate, and low-cost solution for discovering, mitigating, and reporting bots and botnet activity on a network, along with many other types of malicious network attacks Small businesses to large companies Flexible Scalable
Ubuntu – Version 9.10 Snort IDS – Version ◦ IPS Functionality MySQL Basic Analysis and Security Engine (BASE) Barnyard2 – Version Perl VirtualBox – Version Windows XP BackTrack 4
Can vary based on the size of the network Ownership of process Installation ◦ Knowledge to implement solution Maintenance of IDS and BASE ◦ Knowledge to troubleshoot IDS and BASE ◦ Knowledge to script in Perl Analysis of IDS and BASE Receiving and responding to alerts
VirtualBox Install Intrusion Detection System (IDS) Setup ◦ Installation of required software ◦ Configuration of required software Basic Analysis and Security Engine Setup Mitigation Scripting ◦ Perl script to assist with install process Testing ◦ Test to make sure IDS is functioning properly
There is a need for small, medium, and large sized companies to be able to detect and/or mitigate, and report on malicious activity Reporting features Easy-to-implement Accurate Low-cost