{"id":86501,"date":"2020-06-26T07:42:00","date_gmt":"2020-06-26T05:42:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set"},"modified":"2020-06-26T07:42:00","modified_gmt":"2020-06-26T05:42:00","slug":"snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set","status":"publish","type":"post","link":"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set","title":{"rendered":"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/507234\/\">vorig artikel<\/a><\/noindex> We explained how to launch a stable version of Suricata on Ubuntu 18.04 LTS. Setting up an IDS on a single node and connecting free rule sets is quite straightforward. Today, we will explore how to protect a corporate network from the most common types of attacks using Suricata installed on a virtual server. For this, we will need a VDS on Linux with two computing cores. The amount of RAM depends on the load: some may manage with 2 GB, while for more serious tasks, 4 or even 6 GB might be required. The advantage of a virtual machine is the ability to experiment: you can start with a minimal configuration and increase resources as needed.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/508052\/\"><img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/27cd9ba910418444ac7a2b5482f2a8a7.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex>Photo: Reuters<\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/506730\/\">Snort of Suricata. Deel 1: kies een gratis IDS\/IPS voor de bescherming van het bedrijfsnetwerk<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/507234\/\">Snort of Suricata. Deel 2: installatie en initi\u00eble configuratie van Suricata<\/a><\/noindex><\/li>\n<\/ul>\n<p><\/p>\n<h2>Merging Networks<\/h2>\n<p>\nDeploying the IDS on a virtual machine may primarily be needed for testing. If you have never dealt with such solutions before, it's not wise to rush into ordering physical hardware and changing the network architecture. It\u2019s better to safely trial the system without unnecessary costs to determine the computational resource requirements. It's important to understand that all corporate traffic will have to pass through a single external node: to connect the local network (or several networks) to the VDS with the installed IDS Suricata, you can use <noindex><a rel=\"nofollow\" href=\"https:\/\/www.softether.org\/\">SoftEther<\/a><\/noindex> \u2014 an easy-to-configure cross-platform VPN server that provides reliable encryption. Office internet connections may not have a real IP, so it\u2019s better to set it up on a VPS. There are no ready-to-use packages in the Ubuntu repository, so the software will have to be downloaded either from <noindex><a rel=\"nofollow\" href=\"https:\/\/www.softether.org\/\">the project\u2019s website<\/a><\/noindex>, or from an external repository on the service <noindex><a rel=\"nofollow\" href=\"https:\/\/launchpad.net\/~paskal-07\/+archive\/ubuntu\/softethervpn\">Launchpad<\/a><\/noindex> (if you trust it):<\/p>\n<pre><code class=\"bash\">sudo add-apt-repository ppa:paskal-07\/softethervpn\nsudo apt-get update<\/code><\/pre>\n<p>\nYou can view the list of available packages with the following command:<\/p>\n<pre><code class=\"bash\">apt-cache search softether<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/14803c275d46c02a43a52eec9254042c.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWe will need softether-vpnserver (the server in a test configuration is running on VDS), as well as softether-vpncmd \u2014 the command-line utilities for its configuration.<\/p>\n<pre><code class=\"bash\">sudo apt-get install softether-vpnserver softether-vpncmd<\/code><\/pre>\n<p>\nFor server configuration, a special command-line utility is used:<\/p>\n<pre><code class=\"bash\">sudo vpncmd<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/39e1f66848527a771a246aaa9f163933.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWe won't go into detail about the configuration: the procedure is fairly straightforward, and it's well documented in numerous publications, not directly related to the topic of this article. In short, after launching vpncmd, you need to select option 1 to access the server management console. For this, you have to enter the name localhost and press enter instead of entering the hub name. In the console, the administrator password is set with the command serverpasswordset, the virtual hub DEFAULT is deleted (command hubdelete), and a new one named Suricata_VPN is created along with setting its password (command hubcreate). Next, you need to switch to the management console of the new hub using the command hub Suricata_VPN to create a group and a user using the commands groupcreate and usercreate. The user password is set with userpasswordset. <\/p>\n<p>SoftEther supports two traffic transmission modes: SecureNAT and Local Bridge. The first is a proprietary technology for building a virtual private network with its own NAT and DHCP. SecureNAT does not require TUN\/TAP or setting up Netfilter or any other firewall. The routing does not affect the system core, and all processes are virtualized and operate on any VPS\/VDS, regardless of the hypervisor being used. This leads to increased load on the CPU and a decrease in speed compared to the Local Bridge mode, which connects the SoftEther virtual hub to a physical network adapter or TAP device. <\/p>\n<p>Configuration in this case gets complicated, as routing occurs at the kernel level using Netfilter. Our VDS are built on Hyper-V, so at the last step, we create a local bridge and activate the TAP device with the command bridgecreate Suricate_VPN -device:suricate_vpn -tap:yes. After exiting the hub management console, we will see a new network interface in the system that has not yet been assigned an IP:<\/p>\n<pre><code class=\"bash\">ifconfig<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/336fc07fbb44793719789e3f3ce1f124.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNext, we have to enable packet forwarding between interfaces (ip forward) if it is not active:<\/p>\n<pre><code class=\"bash\">sudo nano \/etc\/sysctl.conf<\/code><\/pre>\n<p>\nUncomment the following line:<\/p>\n<pre><code class=\"bash\">net.ipv4.ip_forward = 1<\/code><\/pre>\n<p>\nSave changes in the file, exit the editor, and apply them with the following command:<\/p>\n<pre><code class=\"bash\">sudo sysctl -p<\/code><\/pre>\n<p>\nNext, we need to define a subnet with dummy IPs for the virtual network (for example, 10.0.10.0\/24) and assign the address to the interface:<\/p>\n<pre><code class=\"bash\">sudo ifconfig tap_suricata_vp 10.0.10.1\/24<\/code><\/pre>\n<p>\nThen you will need to specify Netfilter rules.<\/p>\n<p>1. Sta inkomende pakketten toe voor de beluisterde poorten (het SoftEther-protocol maakt gebruik van HTTPS en poort 443)<\/p>\n<pre><code class=\"bash\">sudo iptables -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT\nsudo iptables -A INPUT -p tcp -m tcp --dport 992 -j ACCEPT\nsudo iptables -A INPUT -p tcp -m tcp --dport 1194 -j ACCEPT\nsudo iptables -A INPUT -p udp -m udp --dport 1194 -j ACCEPT\nsudo iptables -A INPUT -p tcp -m tcp --dport 5555 -j ACCEPT<\/code><\/pre>\n<p>\n2. Stel NAT in van het subnet 10.0.10.0\/24 naar het primaire IP van de server<\/p>\n<pre><code class=\"bash\">sudo iptables -t nat -A POSTROUTING -s 10.0.10.0\/24 -j SNAT --to-source 45.132.17.140<\/code><\/pre>\n<p>\n3. Sta doorgang van pakketten toe vanuit het subnet 10.0.10.0\/24<\/p>\n<pre><code class=\"bash\">sudo iptables -A FORWARD -s 10.0.10.0\/24 -j ACCEPT<\/code><\/pre>\n<p>\n4. Sta doorgang van pakketten toe voor reeds gevestigde verbindingen<\/p>\n<pre><code class=\"bash\">sudo iptables -A FORWARD -p all -m state --state ESTABLISHED,RELATED -j ACCEPT<\/code><\/pre>\n<p>\nDe automatisering van het proces bij het opnieuw opstarten van het systeem met behulp van initialisatiescripts laten we aan de lezers als huiswerk. <\/p>\n<p>Als je IP-adressen automatisch aan klanten wilt toewijzen, moet je ook een DHCP-service voor de lokale brug installeren. Hiermee is de serverconfiguratie voltooid en kunnen we naar de clients gaan. SoftEther ondersteunt verschillende protocollen, waarvan het gebruik afhankelijk is van de mogelijkheden van de lokale netwerkinfrastructuur. <\/p>\n<pre><code class=\"bash\">netstat -ap | grep vpnserver<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/42511aeec204ee27b65325d296e30db3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAangezien onze testrouter ook op Ubuntu draait, installeren we de SoftEther-pakketten softether-vpnclient en softether-vpncmd vanuit een externe repository om gebruik te maken van het eigen protocol. We moeten de client starten:<\/p>\n<pre><code class=\"bash\">sudo vpnclient start<\/code><\/pre>\n<p>\nVoor de configuratie gebruiken we de utility vpncmd, waarbij we localhost kiezen als de machine waarop vpnclient draait. Alle commando's worden in de console uitgevoerd: we zullen een virtuele interface (NicCreate) en een account (AccountCreate) moeten aanmaken. <\/p>\n<p>In sommige gevallen moet de authenticatiemethode worden ingesteld met de commando's AccountAnonymousSet, AccountPasswordSet, AccountCertSet en AccountSecureCertSet. Aangezien we geen DHCP gebruiken, wordt het adres voor de virtuele adapter handmatig ingesteld. <\/p>\n<p>Daarnaast moeten we ip forwarding inschakelen (parameter net.ipv4.ip_forward=1 in het bestand \/etc\/sysctl.conf) en statische routes configureren. Indien nodig kan op de VDS met Suricata poorten worden doorgezet voor het gebruik van ge\u00efnstalleerde services in het lokale netwerk. Hiermee is de netwerkintegratie voltooid.<\/p>\n<p>De door ons voorgestelde configuratie zal er ongeveer zo uitzien:<\/p>\n<p><img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/8c650da06420efd25cbb6ed71f37aac2.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h2>Configureren van Suricata<\/h2>\n<p>\nIn <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/507234\/\">vorig artikel<\/a><\/noindex> We discussed two modes of operation for IDS: through the NFQUEUE queue (NFQ mode) and through zero copy (AF_PACKET mode). The second requires two interfaces, but provides higher performance \u2014 we will use this one. The parameter is set by default in \/etc\/default\/suricata. We will also need to edit the vars section in \/etc\/suricata\/suricata.yaml, specifying the virtual subnet as the home network.<\/p>\n<p><img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/b3dc856ba0436de16fbd2ed0f1fa70a9.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nTo restart the IDS, use the command:<\/p>\n<pre><code class=\"bash\">systemctl restart suricata<\/code><\/pre>\n<p>\nThe solution is ready; you may now need to test its resilience against malicious actions.<\/p>\n<h2>Simulating attacks<\/h2>\n<p>\nThere can be several scenarios for the operational application of external IDS services:<\/p>\n<p><b>Protection against DDoS attacks (primary purpose)<\/b><\/p>\n<p>Implementing such an option within a corporate network is challenging, as packets for analysis must pass through the internet-facing interface of the system. Even if the IDS blocks them, parasitic traffic can overwhelm the data transmission channel. To avoid this, it is advisable to order a VPS with a sufficiently powerful internet connection capable of handling all local network traffic as well as all external traffic. Often, this is easier and cheaper than expanding the office channel. As an alternative, one should mention specialized services for DDoS protection. Their service costs are comparable to those of a virtual server, without the need for labor-intensive configuration, but there are drawbacks \u2014 for the price paid, the client only receives DDoS protection, whereas their own IDS can be configured in any way.<\/p>\n<p><b>Protection against other types of external attacks<\/b> <\/p>\n<p>Suricata is capable of handling attempts to exploit various vulnerabilities in internet-accessible corporate network services (email servers, web servers, web applications, etc.). Usually, IDS is installed within the local network after boundary devices, but external deployment is also a viable option.<\/p>\n<p><b>Protection against internal threats<\/b><\/p>\n<p>Ondanks alle inspanningen van de systeembeheerder kunnen de computers in het bedrijfsnetwerk worden besmet met malware. Bovendien verschijnen er soms pestkoppen in het lokale netwerk die proberen onrechtmatige acties uit te voeren. Suricata kan helpen dergelijke pogingen te blokkeren, hoewel het beter is om deze binnen het perimeter te installeren voor de bescherming van het interne netwerk, en deze te gebruiken in combinatie met een beheerde switch die het verkeer naar \u00e9\u00e9n poort kan spiegelen. Een externe IDS is in dit geval ook niet nutteloos \u2013 in ieder geval kan deze pogingen tegenhouden van malware die in het LAN leeft om verbinding te maken met een externe server.<\/p>\n<p>Laten we beginnen met het cre\u00ebren van nog een test aanvallende VPS, terwijl we op de router van het lokale netwerk Apache opzetten met de standaardconfiguratie. Vervolgens zullen we poort 80 van de IDS-server naar hem doorsturen. Vervolgens zullen we een DDoS-aanval imiteren vanuit de aanvallende node. Hiervoor downloaden we een klein programma genaamd xerxes van GitHub, compileren het en starten het op de aanvallende node (mogelijk is de installatie van het gcc-pakket vereist):<\/p>\n<pre><code class=\"bash\">git clone https:\/\/github.com\/Soldie\/xerxes-DDos-zanyarjamal-C.git\ncd xerxes-DDos-zanyarjamal-C\/\ngcc xerxes.c -o xerxes\n.\/xerxes 45.132.17.140 80<\/code><\/pre>\n<p>\nDe uitkomst van zijn werk was als volgt:<\/p>\n<p><img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/80fe4d74ae71cfb16c91336102479670.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSuricata blokkeert de boosdoener, en de standaard Apache-pagina opent, ondanks onze ge\u00efmproviseerde aanval en de vrij trage verbinding van het 'kantoor' (in werkelijkheid thuisnetwerk). Voor serieuzere taken is het de moeite waard om <noindex><a rel=\"nofollow\" href=\"https:\/\/www.metasploit.com\/\">Metasploit Framework<\/a><\/noindex>. Dit is bedoeld voor penetratietests en stelt in staat om verschillende aanvallen te imiteren. De installatie-instructies <noindex><a rel=\"nofollow\" href=\"https:\/\/www.metasploit.com\/get-started\">beschikbaar<\/a><\/noindex> zijn te vinden op de projectwebsite. Na installatie moet er een update worden uitgevoerd:<\/p>\n<pre><code class=\"bash\">sudo msfupdate<\/code><\/pre>\n<p>\nVoor testing starten we msfconsole.<\/p>\n<p><img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/b2a08cf048ae726ca720e942729ed7f8.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHelaas ontbreekt in de laatste versies van het framework de mogelijkheid om automatisch te hacken, dus zullen exploits handmatig moeten worden doorlopen en gestart met het commando use. Eerst moeten we de open poorten op de aanvallende machine identificeren, bijvoorbeeld met nmap (in ons geval kan netstat op de aanvallende node dit prima vervangen), en daarna geschikte <noindex><a rel=\"nofollow\" href=\"https:\/\/www.rapid7.com\/db\/\">Metasploit-modules<\/a><\/noindex>.\u00a0<\/p>\n<p>Er zijn ook andere middelen om de weerbaarheid van IDS tegen aanvallen te testen, inclusief online diensten. Voor de nieuwsgierigen kan men een stresstest uitvoeren met de proefversie van <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ipstresser.com\/\">IP Stresser<\/a><\/noindex>. Om de reacties op de acties van interne kwaadwillenden te controleren, is het raadzaam om speciale tools op een van de machines in het lokale netwerk te installeren. Er zijn talloze opties en het is periodiek aan te raden om deze niet alleen op een experimenteel terrein, maar ook op werk systemen toe te passen. Maar dat is weer een heel ander verhaal.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"http:\/\/ruvds.com\/ru-rub?utm_source=habr&amp;utm_medium=article&amp;utm_campaign=ek&amp;utm_content=snort-ili-suricata-3\"><img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/801a7d4e4fa0aa755205509bd2d26020.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"http:\/\/ruvds.com\/ru-rub?utm_source=habr&amp;utm_medium=article&amp;utm_campaign=ek&amp;utm_content=snort-ili-suricata-3#order\"><img decoding=\"async\" alt=\"Snort of Suricata. Deel 3: het beschermen van het kantoornetwerk\" src=\"\/wp-content\/uploads\/2020\/06\/e2c2a9e30fae35d3a3afaea1915dc106.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><br \/>\n<br \/>Bron: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/508052\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e Suricata \u0432 Ubuntu 18.04 LTS. \u041d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c IDS \u043d\u0430 \u043e\u0434\u043d\u043e\u043c \u0443\u0437\u043b\u0435 \u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u044b\u0435 \u043d\u0430\u0431\u043e\u0440\u044b \u043f\u0440\u0430\u0432\u0438\u043b \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u043d\u0435\u0441\u043b\u043e\u0436\u043d\u043e. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0440\u0430\u0437\u0431\u0435\u0440\u0435\u043c\u0441\u044f, \u043a\u0430\u043a \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 Suricata \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u0443\u044e \u0441\u0435\u0442\u044c \u043e\u043d \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043d\u044b\u0445 \u0432\u0438\u0434\u043e\u0432 \u0430\u0442\u0430\u043a. \u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u043d\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f VDS \u043d\u0430 Linux \u0441 \u0434\u0432\u0443\u043c\u044f \u0432\u044b\u0447\u0438\u0441\u043b\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u043c\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":86502,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-86501","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e Suricata \u0432 Ubuntu 18.04 LTS.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"nl_NL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Snort \u0438\u043b\u0438 Suricata. \u0427\u0430\u0441\u0442\u044c 3: \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c \u043e\u0444\u0438\u0441\u043d\u0443\u044e \u0441\u0435\u0442\u044c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e Suricata \u0432 Ubuntu 18.04 LTS.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-26T05:42:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-26T05:42:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Snort of Suricata. Deel 3: bescherming van het kantoornetwerk | ProHoster","description":"In het vorige artikel hebben we uitgelegd hoe je een stabiele versie van Suricata kunt uitvoeren op Ubuntu 18.04 LTS.","canonical_url":"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"nl_NL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Snort \u0438\u043b\u0438 Suricata. \u0427\u0430\u0441\u0442\u044c 3: \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c \u043e\u0444\u0438\u0441\u043d\u0443\u044e \u0441\u0435\u0442\u044c | ProHoster","og:description":"\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e Suricata \u0432 Ubuntu 18.04 LTS.","og:url":"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-26T05:42:00+00:00","article:modified_time":"2020-06-26T05:42:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"86501","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 13:00:11","updated":"2026-08-11 12:50:14","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/86501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/comments?post=86501"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/86501\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/media\/86502"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/media?parent=86501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/categories?post=86501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/tags?post=86501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}