Download presentation
Presentation is loading. Please wait.
1
Information Networking Security and Assurance Lab National Chung Cheng University Analysis Console for Intrusion Databases
2
Information Networking Security and Assurance Lab National Chung Cheng University 2 Description ACID
3
Information Networking Security and Assurance Lab National Chung Cheng University 3 Objective Setup ACID, MySQL, Snort Super alert Analyzer Performance Benchmarking of ACID
4
Information Networking Security and Assurance Lab National Chung Cheng University 4 About ACID Query-builder and search interface Packet viewer (decoder) Alert management Chart and statistics generation Centralize control
5
Information Networking Security and Assurance Lab National Chung Cheng University 5 System overview ACID+Snort+MySQL ACID
6
Information Networking Security and Assurance Lab National Chung Cheng University 6 Distributed IDS centralize control ACIDDB
7
Information Networking Security and Assurance Lab National Chung Cheng University 7 Prerequisites A database Package: MySQL Version: 3.23.x+ Homepage: http://www.mysql.com/http://www.mysql.com/ A mechanism Package: Snort Version: 1.7+ Homepage: http://www.snort.org/http://www.snort.org/ Package: PHP Version: 4.0.4+ Homepage: http://www.php.net/http://www.php.net/ A web server Package: Apache Server Version: 1.3.*+ Homepage: http://www.apache.org/http://www.apache.org/ PHP access database API Package: ADODB Homepage: http://php.weblogs.com/adodb/http://php.weblogs.com/adodb/ Package: PHPlot Homepage: http://www.phplot.comhttp://www.phplot.com Package: JPGraph Homepage: http://www.aditus.nu/jpgraph/http://www.aditus.nu/jpgraph/ Package: GD Homepage: http://www.boutell.com/gd/http://www.boutell.com/gd/
8
Information Networking Security and Assurance Lab National Chung Cheng University 8 Install ACID and snort Download ACID http://www.andrew.cmu.edu/user/rdanyliw/snort/sno rtacid.html Decompress acid-0.9.6b23.tar.gz Move ACID to your web directory
9
Information Networking Security and Assurance Lab National Chung Cheng University 9 Setting up the database in MySQL Create database Create user and assign privilege Create snort tables
10
Information Networking Security and Assurance Lab National Chung Cheng University 10 Modify ACID config files Edit acid_conf.php
11
Information Networking Security and Assurance Lab National Chung Cheng University 11 Connect to sensor manager Open http://192.168.1.101/acid/acid_conf.php
12
Information Networking Security and Assurance Lab National Chung Cheng University 12 Setup snort output module Edit /etc/snort/snort.conf
13
Information Networking Security and Assurance Lab National Chung Cheng University 13 Test environment 三暝三日 …
14
Information Networking Security and Assurance Lab National Chung Cheng University 14 Enjoy the results Open http://192.168.1.101/acid/
15
Information Networking Security and Assurance Lab National Chung Cheng University 15 More analysis 5 most frequent alerts (alert listing) 15 most frequent alerts (unique source) Time profile of alerts Last 24 hours Last 72 hours
16
Information Networking Security and Assurance Lab National Chung Cheng University 16 Performance Benchmarking of ACID (Page loading time) Host: Intel Mobile 800Mhz, 256 MB RAM OS: Linux 2.2.16-22 Apache: 1.3.19 PHP: 4.0.5 MySQL: 3.23.32 PostgreSQL:7.1.2 DB schema: v102 ACID: 0.9.6b10 - 0.9.6b13
17
Information Networking Security and Assurance Lab National Chung Cheng University 17 I. Unique Alert Listing (acid_stat_alerts.php)
18
Information Networking Security and Assurance Lab National Chung Cheng University 18 II. ACID Main page (acid_main.php)
19
Information Networking Security and Assurance Lab National Chung Cheng University 19 Summary
20
Information Networking Security and Assurance Lab National Chung Cheng University 20 Reference Performance Benchmarking of ACID http://www.andrew.cmu.edu/user/rdanyliw/snort/per f/acid_perf.html NIST Intrusion Detection System
21
Information Networking Security and Assurance Lab National Chung Cheng University 21 Appendix A Passive Ethernet Tap Traffic in Traffic out IDS http://www.snort.org/docs/tap/
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.