{"id":85475,"date":"2020-06-16T13:42:55","date_gmt":"2020-06-16T11:42:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/snort-ili-suricata-chast-1-vybiraem-besplatnuyu-ids-ips-dlya-zashhity-korporativnoj-seti"},"modified":"2020-06-16T13:42:55","modified_gmt":"2020-06-16T11:42:55","slug":"snort-ili-suricata-chast-1-vybiraem-besplatnuyu-ids-ips-dlya-zashhity-korporativnoj-seti","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-1-vybiraem-besplatnuyu-ids-ips-dlya-zashhity-korporativnoj-seti","title":{"rendered":"Snort ose Suricata. Pjesa 1: zgjidhni nj\u00eb IDS\/IPS falas p\u00ebr mbrojtjen e rrjetit t\u00eb korporat\u00ebs","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Disa vite m\u00eb par\u00eb, mbrojtja e nj\u00eb rrjeti lokal ishte e mjaftueshme me nj\u00eb firewall t\u00eb zakonsh\u00ebm dhe programe antivirus, por p\u00ebrball\u00eb sulmeve t\u00eb haker\u00ebve modern\u00eb dhe p\u00ebrhapjes s\u00eb malware-it, ky set \u00ebsht\u00eb tashm\u00eb joefikas. Firewall-i i vjet\u00ebr analizon vet\u00ebm kokat e pakove, duke i lejuar ose bllokuar ato sipas nj\u00eb grupi rregullash formale. Ai nuk di asgj\u00eb p\u00ebr p\u00ebrmbajtjen e pakove, dhe k\u00ebshtu nuk mund t\u00eb njoh\u00eb veprimet telegrafike t\u00eb haker\u00ebve. Programet antivirus nuk e kapin gjithmon\u00eb malware-in, prandaj administratori ka detyr\u00ebn t\u00eb ndjek\u00eb aktivitetin anomalo dhe t\u00eb izoloj\u00eb n\u00eb koh\u00eb hostet e infektuar. <\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/506730\/\"><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 1: zgjidhni nj\u00eb IDS\/IPS falas p\u00ebr mbrojtjen e rrjetit t\u00eb korporat\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/e5bf2d1eeec4b350c9a3b89fdf2a2475.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Ekzistojn\u00eb shum\u00eb mjete t\u00eb avancuara q\u00eb mund t\u00eb mbrojn\u00eb infrastruktur\u00ebn IT t\u00eb kompanis\u00eb. Sot do t\u00eb flasim p\u00ebr sistemet e zbuluarjes dhe parandalimit t\u00eb sulmeve me kod t\u00eb hapur, t\u00eb cilat mund t\u00eb implementohen pa blerjen e pajisjeve dhe licencave t\u00eb shtrenjta p\u00ebr programe.<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Klassifikimi i IDS\/IPS<\/h2>\n<p>\nIDS (Sistemi i Zbulimit t\u00eb Sulmeve) \u00ebsht\u00eb nj\u00eb sistem i dizajnuar p\u00ebr t\u00eb regjistruar veprime t\u00eb dyshimta n\u00eb rrjet ose n\u00eb nj\u00eb kompjuter t\u00eb ve\u00e7ant\u00eb. Ai mban regjistrat e ngjarjeve dhe e njofton personin p\u00ebrgjegj\u00ebs p\u00ebr sigurin\u00eb e informacionit. N\u00eb p\u00ebrb\u00ebrje t\u00eb IDS, mund t\u00eb dallohen elemente t\u00eb ndryshme:<\/p>\n<ul>\n<li>sensor\u00eb p\u00ebr monitorimin e trafikut t\u00eb rrjetit, regjistrat e ndrysh\u00ebm, etj.\u00a0<\/li>\n<li>n\u00ebn-sistemi i analiz\u00ebs q\u00eb identifikon n\u00eb t\u00eb dh\u00ebnat e marra shenja t\u00eb veprimit t\u00eb d\u00ebmsh\u00ebm;<\/li>\n<li>nj\u00eb depo p\u00ebr akumulimin e ngjarjeve fillestare dhe rezultateve t\u00eb analiz\u00ebs;<\/li>\n<li>kona e menaxhimit.<\/li>\n<\/ul>\n<p>\nN\u00eb fillim, IDS klasifikoheshin sipas vendndodhjes: ato mund t\u00eb ishin t\u00eb orientuara p\u00ebr t\u00eb mbrojtur nyjat individuale (host-based ose Host Intrusion Detection System \u2014 HIDS) ose p\u00ebr t\u00eb mbrojtur t\u00ebr\u00eb rrjetin korporativ (network-based ose Network Intrusion Detection System \u2014 NIDS). Vlen t\u00eb p\u00ebrmenden edhe APIDS (Application protocol-based IDS): ato ndjekin nj\u00eb grup t\u00eb kufizuar protokollesh t\u00eb nivelit aplikativ p\u00ebr t\u00eb identifikuar sulme specifike dhe nuk angazhohen n\u00eb analiz\u00ebn e thell\u00eb t\u00eb paketave t\u00eb rrjetit. K\u00ebto produkte zakonisht duken si proxy dhe p\u00ebrdoren p\u00ebr t\u00eb mbrojtur sh\u00ebrbime specifike: servera web dhe aplikacione web (p\u00ebr shembull, t\u00eb shkruara n\u00eb PHP), servera bazash t\u00eb dh\u00ebsh dhe t\u00eb tjer\u00eb. Nj\u00eb p\u00ebrfaq\u00ebsues tipik i k\u00ebsaj klase \u00ebsht\u00eb mod_security p\u00ebr serverin web Apache. <\/p>\n<p>Ne jemi m\u00eb shum\u00eb t\u00eb interesuar p\u00ebr NIDS universale, q\u00eb mb\u00ebshtesin nj\u00eb gam\u00eb t\u00eb gjer\u00eb protokollesh komunikimi dhe teknologji t\u00eb analiz\u00ebs s\u00eb thell\u00eb t\u00eb paketave (DPI - Deep Packet Inspection). Ato monitorojn\u00eb t\u00eb gjith\u00eb trafikun q\u00eb kalon, duke filluar nga niveli i kanalit, dhe identifikojn\u00eb nj\u00eb gam\u00eb t\u00eb gjer\u00eb sulmesh rrjeti, si dhe p\u00ebrpjekje p\u00ebr akses t\u00eb paautorizuar n\u00eb informacion. Shpesh, k\u00ebto sisteme dallohet p\u00ebr arkitektur\u00ebn e tyre t\u00eb shp\u00ebrndar\u00eb dhe mund t\u00eb nd\u00ebrveprojn\u00eb me pajisje t\u00eb ndryshme aktive t\u00eb rrjetit. Vlen t\u00eb p\u00ebrmendim se shum\u00eb NIDS moderne jan\u00eb hibride dhe kombinojn\u00eb disa qasje. N\u00eb var\u00ebsi t\u00eb konfigurimit dhe cil\u00ebsimeve, ato mund t\u00eb zgjidhin detyra t\u00eb ndryshme \u2014 p\u00ebr shembull, mbrojtjen e nj\u00eb nyje ose t\u00ebr\u00eb rrjetin. P\u00ebr m\u00eb tep\u00ebr, funksionet e IDS p\u00ebr stacionet e pun\u00ebs jan\u00eb marr\u00eb p\u00ebrsip\u00ebr nga paketat antivirus, t\u00eb cilat p\u00ebr shkak t\u00eb p\u00ebrhapjes s\u00eb trojan\u00ebve t\u00eb orientuar ndaj vjedhjes s\u00eb informacionit jan\u00eb transformuar n\u00eb firewall-e multifunksionale, t\u00eb cilat gjithashtu zgjidhin detyra t\u00eb identifikimit dhe bllokimit t\u00eb trafikave t\u00eb dyshimta. <\/p>\n<p>Fillimisht, IDS mund t\u00eb identifikonin vet\u00ebm veprimet e malware-it, funksionimin e skanuesve t\u00eb porteve, ose, t\u00eb themi, shkeljet e politikave t\u00eb siguris\u00eb korporative nga ana e p\u00ebrdoruesve. Pasi ndodhte nj\u00eb ngjarje e caktuar, ato informonin administratorin, por shum\u00eb shpejt u kuptua se thjesht identifikimi i nj\u00eb sulmi nuk ishte e mjaftueshme \u2014 ai duhej t\u00eb bllokohej. K\u00ebshtu, IDS u transformuan n\u00eb IPS (Intrusion Prevention Systems) \u2014 sisteme p\u00ebr parandalimin e hyrjeve, t\u00eb afta p\u00ebr t\u00eb bashk\u00ebpunuar me firewall-et e rrjetit.<\/p>\n<h2>Metodat e zb descobrimi<\/h2>\n<p>\nZgjidhjet moderne p\u00ebr zbules\u00ebn dhe parandalimin e nd\u00ebrhyrjeve p\u00ebrdorin metoda t\u00eb ndryshme p\u00ebr identifikimin e aktivitetit t\u00eb d\u00ebmsh\u00ebm, t\u00eb cilat mund t\u00eb klasifikohen n\u00eb tre kategori. Kjo na jep nj\u00eb tjet\u00ebr mund\u00ebsi klasifikimi t\u00eb sistemeve:<\/p>\n<ul>\n<li>IDS\/IPS me n\u00ebnshkresa identifikojn\u00eb n\u00eb trafikun e rrjetit disa modele ose ndjekin ndryshimet n\u00eb gjendjen e sistemeve p\u00ebr t\u00eb p\u00ebrcaktuar nj\u00eb sulm n\u00eb rrjet ose nj\u00eb p\u00ebrpjekje infektimi. Ato praktikisht nuk japin gabime dhe alarme t\u00eb gabuara, por nuk jan\u00eb n\u00eb gjendje t\u00eb zbulojn\u00eb k\u00ebrc\u00ebnime t\u00eb panjohura;<\/li>\n<li>IDS me identifikim anomalish nuk p\u00ebrdorin n\u00ebnshkresa sulmesh. Ato njohin sjelljen q\u00eb largohet nga norma e sistemeve informative (duke p\u00ebrfshir\u00eb anomali n\u00eb trafikun e rrjetit) dhe mund t\u00eb identifikojn\u00eb edhe sulme t\u00eb panjohura. K\u00ebto sisteme japin shum\u00eb alarme t\u00eb gabuara dhe, n\u00eb rast p\u00ebrdorimi t\u00eb gabuar, paralizojn\u00eb funksionimin e rrjetit lokal;<\/li>\n<li>IDS t\u00eb bazuara n\u00eb rregulla veprojn\u00eb sipas parimit: n\u00ebse FAKTI at\u00ebher\u00eb VEPRIMI. N\u00eb thelb, k\u00ebto jan\u00eb sisteme ekspert\u00ebsh me bazat e t\u00eb dh\u00ebnave \u2014 nj\u00eb grup faktesh dhe rregullash logjike. Zgjidhjet e tilla jan\u00eb t\u00eb lodhshme p\u00ebr t'u konfiguruar dhe k\u00ebrkojn\u00eb nga administratori nj\u00eb kuptim t\u00eb detajuar t\u00eb funksionimit t\u00eb rrjetit.\u00a0<\/li>\n<\/ul>\n<p><\/p>\n<h2>Historia e zhvillimit t\u00eb IDS<\/h2>\n<p>\nEpoka e zhvillimit t\u00eb shpejt\u00eb t\u00eb Internetit dhe rrjeteve korporative filloi n\u00eb vitet '90 t\u00eb shekullit t\u00eb kaluar, megjithat\u00eb specialist\u00ebt e siguris\u00eb n\u00eb rrjet ishin t\u00eb shqet\u00ebsuar pak m\u00eb par\u00eb p\u00ebr teknologji m\u00eb t\u00eb avancuara. N\u00eb vitin 1986, Dorothy Denning dhe Peter Neumann publikuan modelin IDES (Intrusion Detection Expert System), i cili u b\u00eb baza e shumic\u00ebs s\u00eb sistemeve moderne p\u00ebr zbules\u00ebn e nd\u00ebrhyrjeve. Ky model p\u00ebrdorte nj\u00eb sistem ekspert p\u00ebr t\u00eb identifikuar llojet e njohura t\u00eb sulmeve, si dhe metoda statistike dhe profile p\u00ebrdoruesish\/sistemi. IDES funksiononte n\u00eb stacionet e pun\u00ebs Sun, duke verifikuar trafikun e rrjetit dhe t\u00eb dh\u00ebnat e aplikacioneve. N\u00eb vitin 1993, doli NIDES (Next-generation Intrusion Detection Expert System) \u2014 nj\u00eb sistem ekspert p\u00ebr zbules\u00ebn e nd\u00ebrhyrjeve t\u00eb gjenerat\u00ebs s\u00eb re.<\/p>\n<p>N\u00eb vitin 1988, nga puna e Denning dhe Neumann, u shfaq sistemi ekspert MIDAS (Multics intrusion detection and alerting system), i cili p\u00ebrdorte P-BEST dhe LISP. Po at\u00ebher\u00eb u krijua edhe sistemi Haystack, i bazuar n\u00eb metoda statistikore. Nj\u00eb detektor tjet\u00ebr statistik t\u00eb anomalive, W&amp;S (Wisdom &amp; Sense), u zhvillua n\u00eb vitin pasues n\u00eb Laboratorin Komb\u00ebtar Los Alamos. Rritja e industris\u00eb shkonte me ritme t\u00eb shpejta. P\u00ebr shembull, n\u00eb vitin 1990, n\u00eb sistemin TIM (Time-based inductive machine) tashm\u00eb ishte realizuar zbulimi i anomalive duke p\u00ebrdorur m\u00ebsimin induktiv mbi modelet e p\u00ebrdoruesve t\u00eb nj\u00ebpasnj\u00ebshme (gjuha Common LISP). NSM (Network Security Monitor) p\u00ebr zbulimin e anomalive krahasoi matricat e aksesit, nd\u00ebrsa ISOA (Information Security Officer\u2019s Assistant) mb\u00ebshteti strategji t\u00eb ndryshme zbulimi: metoda statistikore, kontrollin e profilit dhe sistemin ekspert. Sistemi ComputerWatch e krijuar n\u00eb AT&amp;T Bell Labs p\u00ebrdorte edhe metoda statistikore dhe rregulla p\u00ebr kontroll, dhe prototipi i par\u00eb i IDS t\u00eb shp\u00ebrndar\u00eb u zhvillua nga zhvilluesit e Universitetit t\u00eb Kalifornis\u00eb n\u00eb vitin 1991 \u2014 DIDS (Distributed intrusion detection system) e cila gjithashtu ishte nj\u00eb sistem ekspert.<\/p>\n<p>Fillimisht, IDS-t\u00eb ishin pronar\u00eb, por n\u00eb vitin 1998, Laboratori Komb\u00ebtar Lawrence n\u00eb Berkeley l\u00ebshoi Bro (n\u00eb vitin 2018 ajo u riem\u00ebrua n\u00eb Zeek) \u2014 nj\u00eb sistem me kod t\u00eb hapur, q\u00eb p\u00ebrdorte nj\u00eb gjuh\u00eb rregullash t\u00eb vet\u00ebn p\u00ebr analizimin e t\u00eb dh\u00ebnave libpcap. N\u00eb n\u00ebntor t\u00eb atij viti u shfaq edhe skaneri i paketave APE i cili p\u00ebrdorte libpcap, i cili muajin pasues u riem\u00ebrua n\u00eb Snort dhe m\u00eb von\u00eb u b\u00eb nj\u00eb IDS\/IPS i plot\u00eb. At\u00ebher\u00eb filluan t\u00eb shfaqen edhe shum\u00eb zgjidhje proprietar\u00eb. <\/p>\n<h2>Snort dhe Suricata<\/h2>\n<p>\nShum\u00eb kompani preferojn\u00eb IDS\/IPS falas me kod t\u00eb hapur. P\u00ebr nj\u00eb koh\u00eb t\u00eb gjat\u00eb, zgjidhja standarde ishte Snort, por tani ajo \u00ebsht\u00eb z\u00ebvend\u00ebsuar nga sistemi Suricata. Le t\u00eb shqyrtojm\u00eb p\u00ebrfitimet dhe disavantazhet e tyre pak m\u00eb n\u00eb detaje. Snort kombinon avantazhet e metod\u00ebs s\u00eb n\u00ebnshkrimit me mund\u00ebsin\u00eb e zbulimit t\u00eb anomalive n\u00eb koh\u00eb reale. Suricata gjithashtu lejon p\u00ebrdorimin e metodave t\u00eb tjera p\u00ebrve\u00e7 njohjes s\u00eb sulmeve me n\u00ebnshkrime. Sistemi u krijua nga nj\u00eb grup zhvilluesish q\u00eb u ndan\u00eb nga projekti Snort dhe mb\u00ebshtet funksionet IPS q\u00eb nga versioni 1.4, nd\u00ebrsa n\u00eb Snort mund\u00ebsia p\u00ebr t\u00eb parandaluar dep\u00ebrtimet u shfaq m\u00eb von\u00eb. <\/p>\n<p>Dallimi kryesor midis dy produkteve t\u00eb njohura konsiston n\u00eb faktin se Suricata ka mund\u00ebsin\u00eb p\u00ebr t\u00eb p\u00ebrdorur GPU p\u00ebr llogaritje n\u00eb modalitetin IDS, si dhe nj\u00eb IPS m\u00eb t\u00eb avancuar. Sistemi \u00ebsht\u00eb nd\u00ebrtuar fillimisht p\u00ebr shum\u00ebprocese, nd\u00ebrsa Snort \u00ebsht\u00eb nj\u00eb produkt nj\u00ebprocese. P\u00ebr shkak t\u00eb historis\u00eb s\u00eb tij t\u00eb gjat\u00eb dhe kodit t\u00eb trash\u00ebguar, ai nuk e p\u00ebrdor optimalisht platform\u00ebn harduerike shum\u00ebpro\u00e7esore\/multikristinore, nd\u00ebrsa Suricata n\u00eb kompjuter\u00ebt e zakonsh\u00ebm lejon p\u00ebrpunimin e trafikut deri n\u00eb 10 Gbit\/s. Mund t\u00eb flitet gjat\u00eb p\u00ebr ngjashm\u00ebrit\u00eb dhe dallimet e dy sistemeve, por ndon\u00ebse engine Suricata funksionon m\u00eb shpejt, p\u00ebr kanalet jo shum\u00eb t\u00eb gjera, kjo nuk ka r\u00ebnd\u00ebsi thelb\u00ebsore.<\/p>\n<h2>Mund\u00ebsi t\u00eb Implementimit<\/h2>\n<p>\nIPS duhet t\u00eb vendoset n\u00eb nj\u00eb m\u00ebnyr\u00eb t\u00eb till\u00eb q\u00eb sistemi t\u00eb mund t\u00eb v\u00ebzhgoj\u00eb segmentet e rrjetit q\u00eb kontrollon. M\u00eb s\u00eb shpeshti, kjo \u00ebsht\u00eb nj\u00eb kompjuter i dedikuar, nj\u00eb nd\u00ebrfaqe e t\u00eb cilit lidhet pas pajisjeve kufitare dhe 'shikon' p\u00ebrmes tyre n\u00eb rrjetet e paprotectuara t\u00eb internetit. Nj\u00eb nd\u00ebrfaqe tjet\u00ebr e IPS-s\u00eb lidhet n\u00eb hyrje t\u00eb segmentit t\u00eb mbrojtur, n\u00eb m\u00ebnyr\u00eb q\u00eb e gjith\u00eb trafiku t\u00eb kaloj\u00eb p\u00ebrmes sistemit dhe t\u00eb analizohet. N\u00eb raste m\u00eb t\u00eb nd\u00ebrlikuara, mund t\u00eb ket\u00eb disa segmente mbrojtjeje: p\u00ebr shembull, n\u00eb rrjetet e korporatave shpesh cakohet nj\u00eb zon\u00eb t\u00eb demilitarizuar (DMZ) me sh\u00ebrbime t\u00eb aksesueshme nga interneti. <\/p>\n<p><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 1: zgjidhni nj\u00eb IDS\/IPS falas p\u00ebr mbrojtjen e rrjetit t\u00eb korporat\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/15e2e449a81eedea09032718ff4a1bc9.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNj\u00eb IPS e till\u00eb mund t\u00eb parandaloj\u00eb p\u00ebrpjekjet p\u00ebr skanimin e porteve ose thyerjen e siguris\u00eb p\u00ebrmes p\u00ebrmendjes s\u00eb fjal\u00ebve kaluese, shfryt\u00ebzimin e dob\u00ebsive n\u00eb serverin e post\u00ebs, serverin web ose n\u00eb skriptet e tjera, si dhe lloje t\u00eb tjera t\u00eb sulmeve t\u00eb jashtme. N\u00ebse kompjuter\u00ebt n\u00eb rrjetin lokal infektohen me malware, IDS nuk do t'i lejoj\u00eb ata t\u00eb lidhen me serverat e botnet-it q\u00eb ndodhen jasht\u00eb. P\u00ebr nj\u00eb mbrojtje m\u00eb serioze t\u00eb rrjetit t\u00eb brendsh\u00ebm, me siguri do t\u00eb nevojitet nj\u00eb konfigurim kompleks me nj\u00eb sistem t\u00eb shp\u00ebrndara dhe me switch-e t\u00eb menaxhuar t\u00eb shtrenjt\u00eb, t\u00eb aft\u00eb p\u00ebr t\u00eb pasqyruar trafikun p\u00ebr nj\u00eb nga portat e nd\u00ebrfaqes IDS.<\/p>\n<p>Shpesh, rrjetet korporative p\u00ebrballen me sulme t\u00eb shp\u00ebrndara, t\u00eb cilat kan\u00eb p\u00ebr q\u00ebllim t\u00eb shkaktojn\u00eb nd\u00ebrprerje sh\u00ebrbimi (DDoS). Edhe pse IDS-t\u00eb moderne jan\u00eb t\u00eb afta t'i luftojn\u00eb ato, opsioni i sip\u00ebrp\u00ebrmendur i implementimit k\u00ebtu ndihmon pak. Sistemi njeh aktivitetin e d\u00ebmsh\u00ebm dhe bllokon trafikun parazit, por p\u00ebr k\u00ebt\u00eb q\u00ebllim paketat duhet t\u00eb kalojn\u00eb p\u00ebrmes nj\u00eb lidhjeje t\u00eb jashtme me internetin dhe t\u00eb arrijn\u00eb n\u00eb nd\u00ebrfaqen e saj rrjetore. N\u00eb var\u00ebsi t\u00eb intensitetit t\u00eb sulmit, kanali i transmetimit t\u00eb dh\u00ebnave mund t\u00eb mos p\u00ebrballoj\u00eb ngarkes\u00ebn dhe objekti i haker\u00ebve do t\u00eb arrihet. P\u00ebr raste t\u00eb tilla, rekomandojm\u00eb q\u00eb t\u00eb implementoni IDS n\u00eb nj\u00eb server virtual me nj\u00eb lidhje interneti sigurisht m\u00eb t\u00eb fuqishme. Mund t\u00eb lidhni VPS-in me rrjetin lokal p\u00ebrmes VPN, dhe pastaj do t\u00eb nevojitet t\u00eb konfigurohet p\u00ebrmes tij routing-u i t\u00eb gjith\u00eb trafikut t\u00eb jasht\u00ebm. At\u00ebher\u00eb, n\u00eb rastin e sulmit DDoS, nuk do t\u00eb nevojitet t\u00eb kaloni paketat p\u00ebrmes lidhjes me ofruesin, ato do t\u00eb bllokohen n\u00eb nyj\u00ebn e jashtme.<\/p>\n<p><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 1: zgjidhni nj\u00eb IDS\/IPS falas p\u00ebr mbrojtjen e rrjetit t\u00eb korporat\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/7ced164023bf2aa37e676d460804d6da.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h2>Problemi i zgjedhjes<\/h2>\n<p>\nT\u00eb identifikosh liderin midis sistemeve falas \u00ebsht\u00eb shum\u00eb e v\u00ebshtir\u00eb. Zgjedhja e IDS\/IPSeve p\u00ebrcaktohet nga topologjia e rrjetit, funksionet mbrojt\u00ebse t\u00eb nevojshme, si dhe preferencat personale t\u00eb administratorit dhe d\u00ebshira e tij p\u00ebr t\u00eb u marr\u00eb me konfigurimet. Snort ka nj\u00eb histori m\u00eb t\u00eb gjat\u00eb dhe \u00ebsht\u00eb m\u00eb mir\u00eb i dokumentuar, edhe pse informacioni mbi Suricata gjithashtu nuk \u00ebsht\u00eb e v\u00ebshtir\u00eb p\u00ebr t'u gjetur n\u00eb internet. N\u00eb \u00e7do rast, p\u00ebr t\u00eb zot\u00ebruar sistemin do t\u00eb duhet t\u00eb b\u00ebsh disa p\u00ebrpjekje, t\u00eb cilat p\u00ebrfundimisht do t\u00eb kompensohen \u2014 IDS\/IPSer\u00ebt komercial\u00eb harduer dhe harduer-software jan\u00eb mjaft t\u00eb shtrenjt\u00eb dhe nuk jan\u00eb gjithmon\u00eb brenda buxhetit. Nuk ka asgj\u00eb p\u00ebr t\u00eb penduar p\u00ebr koh\u00ebn e humbur, sepse nj\u00eb administrator i mir\u00eb gjithmon\u00eb p\u00ebrmir\u00ebson kualifikimet p\u00ebrmes pun\u00ebdh\u00ebn\u00ebsit. N\u00eb k\u00ebt\u00eb situat\u00eb, t\u00eb gjith\u00eb p\u00ebrfitojn\u00eb. N\u00eb artikullin e ardhsh\u00ebm do t\u00eb shqyrtojm\u00eb disa mund\u00ebsi implementimi p\u00ebr Suricata dhe do t\u00eb krahasojm\u00eb n\u00eb praktik\u00eb sistemin m\u00eb modern me IDS\/IPSn klasike Snort.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"http:\/\/ruvds.com\/ru-rub?utm_source=habr&amp;utm_medium=article&amp;utm_campaign=ek&amp;utm_content=snort-ili-suricata\"><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 1: zgjidhni nj\u00eb IDS\/IPS falas p\u00ebr mbrojtjen e rrjetit t\u00eb korporat\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/19f0fd87faf30e31d34e2a10421514da.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"http:\/\/ruvds.com\/ru-rub?utm_source=habr&amp;utm_medium=article&amp;utm_campaign=ek&amp;utm_content=snort-ili-suricata#order\"><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 1: zgjidhni nj\u00eb IDS\/IPS falas p\u00ebr mbrojtjen e rrjetit t\u00eb korporat\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/a5fe3bac97102322110b9d0e33f3919c.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/506730\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u0433\u0434\u0430-\u0442\u043e \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u044b\u043b\u043e \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043e\u0431\u044b\u043a\u043d\u043e\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u0445 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c, \u043d\u043e \u043f\u0440\u043e\u0442\u0438\u0432 \u0430\u0442\u0430\u043a \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u0445\u0430\u043a\u0435\u0440\u043e\u0432 \u0438 \u0440\u0430\u0441\u043f\u043b\u043e\u0434\u0438\u0432\u0448\u0435\u0439\u0441\u044f \u0432 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u0432\u0440\u0435\u043c\u044f \u043c\u0430\u043b\u0432\u0430\u0440\u0438 \u0442\u0430\u043a\u043e\u0439 \u043d\u0430\u0431\u043e\u0440 \u0443\u0436\u0435 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u0435\u043d. \u0421\u0442\u0430\u0440\u044b\u0439-\u0434\u043e\u0431\u0440\u044b\u0439 firewall \u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u0435\u0442 \u0442\u043e\u043b\u044c\u043a\u043e \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u043f\u0440\u043e\u043f\u0443\u0441\u043a\u0430\u044f \u0438\u043b\u0438 \u0431\u043b\u043e\u043a\u0438\u0440\u0443\u044f \u0438\u0445 \u0432 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0438 \u0441 \u043d\u0430\u0431\u043e\u0440\u043e\u043c \u0444\u043e\u0440\u043c\u0430\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0430\u0432\u0438\u043b. \u041e \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u043c \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u043e\u043d \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u0437\u043d\u0430\u0435\u0442, \u0430 \u043f\u043e\u0442\u043e\u043c\u0443 \u043d\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":85476,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-85475","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u0433\u0434\u0430-\u0442\u043e \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u044b\u043b\u043e \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043e\u0431\u044b\u043a\u043d\u043e\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u0445 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c, \u043d\u043e \u043f\u0440\u043e\u0442\u0438\u0432 \u0430\u0442\u0430\u043a \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u0445\u0430\u043a\u0435\u0440\u043e\u0432 \u0438 \u0440\u0430\u0441\u043f\u043b\u043e\u0434\u0438\u0432\u0448\u0435\u0439\u0441\u044f \u0432 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u0432\u0440\u0435\u043c\u044f \u043c\u0430\u043b\u0432\u0430\u0440\u0438 \u0442\u0430\u043a\u043e\u0439 \u043d\u0430\u0431\u043e\u0440 \u0443\u0436\u0435 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-1-vybiraem-besplatnuyu-ids-ips-dlya-zashhity-korporativnoj-seti\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Snort \u0438\u043b\u0438 Suricata. \u0427\u0430\u0441\u0442\u044c 1: \u0432\u044b\u0431\u0438\u0440\u0430\u0435\u043c \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u0443\u044e IDS\/IPS \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u0433\u0434\u0430-\u0442\u043e \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u044b\u043b\u043e \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043e\u0431\u044b\u043a\u043d\u043e\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u0445 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c, \u043d\u043e \u043f\u0440\u043e\u0442\u0438\u0432 \u0430\u0442\u0430\u043a \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u0445\u0430\u043a\u0435\u0440\u043e\u0432 \u0438 \u0440\u0430\u0441\u043f\u043b\u043e\u0434\u0438\u0432\u0448\u0435\u0439\u0441\u044f \u0432 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u0432\u0440\u0435\u043c\u044f \u043c\u0430\u043b\u0432\u0430\u0440\u0438 \u0442\u0430\u043a\u043e\u0439 \u043d\u0430\u0431\u043e\u0440 \u0443\u0436\u0435 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-1-vybiraem-besplatnuyu-ids-ips-dlya-zashhity-korporativnoj-seti\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-16T11:42:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-16T11:42:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Snort apo Suricata. Pjesa 1: Zgjidhni nj\u00eb IDS\/IPSa falas p\u00ebr mbrojtjen e rrjetit korporativ | ProHoster","description":"Dikur, p\u00ebr t\u00eb mbrojtur rrjetin lokal, mjaftonte nj\u00eb firewall i zakonsh\u00ebm dhe programe antivirus, por p\u00ebrball\u00eb sulmeve nga haker\u00ebt modern\u00eb dhe shp\u00ebrndarjes s\u00eb fundit t\u00eb malware-it, ky grup tashm\u00eb nuk \u00ebsht\u00eb mjaftuesh\u00ebm.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-1-vybiraem-besplatnuyu-ids-ips-dlya-zashhity-korporativnoj-seti","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Snort \u0438\u043b\u0438 Suricata. \u0427\u0430\u0441\u0442\u044c 1: \u0432\u044b\u0431\u0438\u0440\u0430\u0435\u043c \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u0443\u044e IDS\/IPS \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 | ProHoster","og:description":"\u041a\u043e\u0433\u0434\u0430-\u0442\u043e \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u0431\u044b\u043b\u043e \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043e\u0431\u044b\u043a\u043d\u043e\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u044d\u043a\u0440\u0430\u043d\u0430 \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u0445 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c, \u043d\u043e \u043f\u0440\u043e\u0442\u0438\u0432 \u0430\u0442\u0430\u043a \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u0445\u0430\u043a\u0435\u0440\u043e\u0432 \u0438 \u0440\u0430\u0441\u043f\u043b\u043e\u0434\u0438\u0432\u0448\u0435\u0439\u0441\u044f \u0432 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u0432\u0440\u0435\u043c\u044f \u043c\u0430\u043b\u0432\u0430\u0440\u0438 \u0442\u0430\u043a\u043e\u0439 \u043d\u0430\u0431\u043e\u0440 \u0443\u0436\u0435 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-1-vybiraem-besplatnuyu-ids-ips-dlya-zashhity-korporativnoj-seti","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-16T11:42:55+00:00","article:modified_time":"2020-06-16T11:42:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"85475","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:36:28","updated":"2026-08-11 12:50:15","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/85475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=85475"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/85475\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/85476"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=85475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=85475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=85475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}