{"id":85990,"date":"2020-06-21T01:42:12","date_gmt":"2020-06-20T23:42:12","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/snort-ili-suricata-chast-2-ustanovka-i-pervichnaya-nastrojka-suricata"},"modified":"2020-06-21T01:42:12","modified_gmt":"2020-06-20T23:42:12","slug":"snort-ili-suricata-chast-2-ustanovka-i-pervichnaya-nastrojka-suricata","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-2-ustanovka-i-pervichnaya-nastrojka-suricata","title":{"rendered":"Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Sipas statistikave, volumi i trafikut n\u00eb rrjet rritet me rreth 50% \u00e7do vit. Kjo \u00e7on n\u00eb rritjen e ngarkes\u00ebs n\u00eb pajisje dhe, n\u00eb ve\u00e7anti, rrit k\u00ebrkesat p\u00ebr performanc\u00ebn e IDS\/IPS. Mund t\u00eb blini pajisje t\u00eb shtrenjta t\u00eb specializuara, por ka nj\u00eb opsion m\u00eb t\u00eb lir\u00eb \u2013 implementimi i nj\u00eb prej sistemeve me burim t\u00eb hapur. Shum\u00eb administrator\u00eb fillestar\u00eb mendojn\u00eb se instalimi dhe konfiguroja e nj\u00eb IPS falas \u00ebsht\u00eb mjaft e komplikuar. N\u00eb rastin e Suricata, kjo nuk \u00ebsht\u00eb plot\u00ebsisht e v\u00ebrtet\u00eb \u2013 mund ta instaloni dhe t\u00eb filloni t\u00eb bllokoni sulme standarde me nj\u00eb grup rregullash falas brenda disa minutash.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/507234\/\"><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata\" src=\"\/wp-content\/uploads\/2020\/06\/38b577d1359bfd99ca1f4c7510d8563b.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/506730\/\">Snort ose Suricata. Pjesa 1: zgjedhja e nj\u00eb IDS\/IPS falas p\u00ebr mbrojtjen e rrjetit t\u00eb kompanis\u00eb<\/a><\/noindex><\/p>\n<h2>Pse \u00ebsht\u00eb e nevojshme nj\u00eb IPS tjet\u00ebr e hapur?<\/h2>\n<p>\nSistemi Snort, i cili shum\u00eb koh\u00eb \u00ebsht\u00eb konsideruar standard, \u00ebsht\u00eb zhvilluar q\u00eb nga fundi i viteve '90, prandaj fillimisht ishte nj\u00eb proces nj\u00ebkan\u00ebsh. Gjat\u00eb viteve t\u00eb kaluara, ajo ka fituar t\u00eb gjitha funksionalitetet moderne, si mb\u00ebshtetje p\u00ebr IPv6, mund\u00ebsin\u00eb p\u00ebr analizimin e protokolleve t\u00eb nivelit aplikativ dhe nj\u00eb moduli universal t\u00eb aksesit n\u00eb t\u00eb dh\u00ebna. <\/p>\n<p>Motori baz\u00eb Snort 2.X ka m\u00ebsuar t\u00eb punoj\u00eb me disa b\u00ebrthama, por ka mbetur ende nj\u00ebkan\u00ebsh dhe, p\u00ebr k\u00ebt\u00eb arsye, nuk mund t\u00eb shfryt\u00ebzoj\u00eb optimalisht avantazhet e platformave moderne t\u00eb harduerit. <\/p>\n<p>Problemi u zgjidh n\u00eb versionin e tret\u00eb t\u00eb sistemit, por p\u00ebrgatitjet zgjat\u00ebn kaq shum\u00eb saq\u00eb n\u00eb treg doli Suricata, e shkruar nga e para. N\u00eb vitin 2009, ajo filloi t\u00eb zhvillohej pik\u00ebrisht si nj\u00eb alternativ\u00eb shum\u00ebkan\u00ebshe ndaj Snort, duke pasur funksionalitetet e IPS menj\u00ebher\u00eb t\u00eb gatshme. Kodi shp\u00ebrndahet n\u00ebn licenc\u00ebn GPLv2, por partner\u00ebt financiar\u00eb t\u00eb projektit kan\u00eb akses n\u00eb versionin e mbyllur t\u00eb motorit. Disa probleme me shkall\u00ebzimin n\u00eb versionet e para t\u00eb sistemit u shfaq\u00ebn, por ato u zgjidh\u00ebn mjaft shpejt.<\/p>\n<h2>Pse Suricata?<\/h2>\n<p>\nN\u00eb Suricata ka disa module (ashtu si n\u00eb Snort): kapja, mbledhja, dekodimi, zbulimi dhe dalja. N\u00eb m\u00ebnyr\u00eb standarde, trafiku i kapur kalon p\u00ebrmes nj\u00eb dobi e nj\u00ebkan\u00ebve deri n\u00eb dekodim, edhe pse kjo e ngarkon m\u00eb shum\u00eb sistemin. N\u00ebse \u00ebsht\u00eb e nevojshme, rrjedhat mund t\u00eb ndahen n\u00eb cil\u00ebsimet dhe t\u00eb shp\u00ebrndahen n\u00eb procesor\u00eb \u2013 Suricata optimizohet shum\u00eb mir\u00eb p\u00ebr harduerin specifik, edhe pse kjo nuk \u00ebsht\u00eb m\u00eb nivel i HOWTO p\u00ebr fillestar\u00ebt. Vlen t\u00eb theksohet gjithashtu prania n\u00eb Suricata e mjeteve t\u00eb avancuara t\u00eb inspektimit HTTP t\u00eb bazuara n\u00eb bibliotek\u00ebn HTP. Ato gjithashtu mund t\u00eb p\u00ebrdoren p\u00ebr t\u00eb regjistruar trafikun pa e zbuluar at\u00eb. Sistemi gjithashtu mb\u00ebshtet dekodimin IPv6, p\u00ebrfshir\u00eb tunelimin IPv4-in-IPv6, IPv6-in-IPv6 dhe t\u00eb tjer\u00eb. <\/p>\n<p>P\u00ebr kapjen e trafikut mund t\u00eb p\u00ebrdoren interface t\u00eb ndryshme (NFQueue, IPFRing, LibPcap, IPFW, AF_PACKET, PF_RING), dhe n\u00eb modalitetin Unix Socket mund t\u00eb analizoni automatikisht skedar\u00ebt PCAP t\u00eb kapur nga sniffer t\u00eb tjer\u00eb. P\u00ebr m\u00eb tep\u00ebr, arkitektura modulare e Suricata e leht\u00ebson lidhjen e elementeve t\u00eb reja p\u00ebr kapjen, dekodimin, analizimin dhe p\u00ebrpunimin e paketave rrjet. \u00cbsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb theksohet gjithashtu se bllokimi i trafikut n\u00eb Suricata \u00ebsht\u00eb realizuar p\u00ebrmes mjeteve t\u00eb filtrit operacional t\u00eb sistemit. N\u00eb GNU\/Linux ka dy variante t\u00eb funksionimit IPS: p\u00ebrmes radh\u00ebs NFQUEUE (modaliteti NFQ) dhe p\u00ebrmes zero copy (modaliteti AF_PACKET). N\u00eb rastin e par\u00eb, paketa q\u00eb kalon n\u00eb iptables d\u00ebrgohet n\u00eb radh\u00ebn NFQUEUE, ku mund t\u00eb p\u00ebrpunohen n\u00eb nivelin e p\u00ebrdoruesit. Suricata e kalon at\u00eb p\u00ebrmes rregullave t\u00eb saj dhe jep nj\u00eb nga tre verdiktet: NF_ACCEPT, NF_DROP dhe NF_REPEAT. Dy t\u00eb parat nuk k\u00ebrkojn\u00eb shpjegime, nd\u00ebrsa e fundit lejon q\u00eb t\u00eb etiketohen paketat dhe t'i d\u00ebrgojn\u00eb ato n\u00eb fillim t\u00eb tabel\u00ebs aktuale t\u00eb iptables. Modaliteti AF_PACKET ka nj\u00eb shpejt\u00ebsi m\u00eb t\u00eb lart\u00eb, por i imponon sistemit nj\u00eb s\u00ebr\u00eb kufizimesh: duhet t\u00eb ket\u00eb dy interface rrjeti dhe t\u00eb funksionoj\u00eb si nj\u00eb der\u00ebdal\u00ebse. Paketa e bllokuar thjesht nuk d\u00ebrgohet n\u00eb interface-in e dyt\u00eb. <\/p>\n<p>Nj\u00eb karakteristik\u00eb e r\u00ebnd\u00ebsishme e Suricata \u00ebsht\u00eb mund\u00ebsia e p\u00ebrdorimit t\u00eb burimeve t\u00eb Snort. Administrator\u00ebt kan\u00eb akses, nd\u00ebr t\u00eb tjera, n\u00eb setet e rregullave t\u00eb Sourcefire VRT dhe OpenSource Emerging Threats, si dhe n\u00eb komerciale Emerging Threats Pro. T\u00eb dh\u00ebnat e unifikuara mund t\u00eb analizohen me an\u00eb t\u00eb backend-eve t\u00eb njohura, si dhe mb\u00ebshtetet dalja n\u00eb PCAP dhe Syslog. Cil\u00ebsimet e sistemit dhe rregullat ruhen n\u00eb skedar\u00eb me formatin YAML, i cili \u00ebsht\u00eb leht\u00eb i lexuesh\u00ebm dhe mund t\u00eb p\u00ebrpunohet automatikisht. Motori Suricata njeh shum\u00eb protokolle, prandaj n\u00eb rregulla nuk \u00ebsht\u00eb nevoja t\u00eb lidhemi me numrin e portit. P\u00ebr m\u00eb tep\u00ebr, n\u00eb rregullat e Suricata aktivizohet koncepti i flowbits. P\u00ebr t\u00eb ndjekur aktivizimin p\u00ebrdoren variabla sesioni, t\u00eb cilat mund\u00ebsojn\u00eb krijimin dhe aplikimin e ndryshimeve t\u00eb ndryshme me numra dhe flamuj. Shum\u00eb IDS-i i konsiderojn\u00eb lidhjet e ndryshme TCP si entitete t\u00eb ve\u00e7anta dhe mund t\u00eb mos shohin lidhjet midis tyre, q\u00eb tregojn\u00eb fillimin e nj\u00eb sulmi. Suricata p\u00ebrpiqet t\u00eb shoh\u00eb gjith\u00e7ka nga nj\u00eb perspektiv\u00eb m\u00eb t\u00eb gjer\u00eb dhe n\u00eb shum\u00eb raste njeh qarkullimin e d\u00ebmsh\u00ebm t\u00eb shp\u00ebrndar\u00eb n\u00eb lidhje t\u00eb ndryshme. Mund t\u00eb flasim gjat\u00eb p\u00ebr avantazhet e saj, por le t\u00eb kalojm\u00eb n\u00eb instalimin dhe konfigurimin e saj.<\/p>\n<h2>Si ta instaloni?<\/h2>\n<p>\nNe do t\u00eb instalojm\u00eb Suricata n\u00eb nj\u00eb server virtual q\u00eb funksionon n\u00ebn Ubuntu 18.04 LTS. T\u00eb gjitha komandat duhet t\u00eb ekzekutohen me emrin e superadministratori (root). Opsioni m\u00eb i sigurt \u00ebsht\u00eb t\u00eb lidhemi n\u00eb serverin p\u00ebrmes SSH si nj\u00eb p\u00ebrdorues i zakonsh\u00ebm dhe pastaj t\u00eb p\u00ebrdorim utilitarin sudo p\u00ebr t\u00eb p\u00ebrmir\u00ebsuar privilegjet. S\u00eb pari, duhet t\u00eb instalojm\u00eb paketat q\u00eb na nevojiten:<\/p>\n<pre><code class=\"bash\">sudo apt -y install libpcre3 libpcre3-dev build-essential autoconf automake libtool libpcap-dev libnet1-dev libyaml-0-2 libyaml-dev zlib1g zlib1g-dev libmagic-dev libcap-ng-dev libjansson-dev pkg-config libnetfilter-queue-dev geoip-bin geoip-database geoipupdate apt-transport-https<\/code><\/pre>\n<p>\nShtojm\u00eb nj\u00eb depo t\u00eb jashtme:<\/p>\n<pre><code class=\"bash\">sudo add-apt-repository ppa:oisf\/suricata-stable\nsudo apt-get update<\/code><\/pre>\n<p>\nInstalojm\u00eb versionin m\u00eb t\u00eb fundit stabil t\u00eb Suricata:<\/p>\n<pre><code class=\"bash\">sudo apt-get install suricata<\/code><\/pre>\n<p>\nN\u00ebse \u00ebsht\u00eb e nevojshme, rregullojm\u00eb skedar\u00ebt e konfigurimit duke z\u00ebvend\u00ebsuar emrin e p\u00ebrdorur standart, eth0, me emrin e v\u00ebrtet\u00eb t\u00eb nd\u00ebrfaqes s\u00eb jashtme t\u00eb serverit. Cil\u00ebsimet standart ruhen n\u00eb skedarin \/etc\/default\/suricata, nd\u00ebrsa ato t\u00eb p\u00ebrdoruesit ruhen n\u00eb \/etc\/suricata\/suricata.yaml. Konfigurimi i IDS zakonisht kufizohet n\u00eb rregullimin e k\u00ebtij skedari konfigurimi. Nj\u00eb s\u00ebr\u00eb parametrash n\u00eb t\u00eb p\u00ebrputhen me ato nga Snort, p\u00ebrsa i p\u00ebrket emrave dhe q\u00ebllimeve. Megjithat\u00eb, sintaksa \u00ebsht\u00eb krejt\u00ebsisht ndryshe, por skedari \u00ebsht\u00eb m\u00eb i leht\u00eb p\u00ebr t'u lexuar sesa ato t\u00eb Snort, dhe p\u00ebr m\u00eb tep\u00ebr, ai \u00ebsht\u00eb mir\u00ebkomentuar.<\/p>\n<pre><code class=\"bash\">sudo nano \/etc\/default\/suricata<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata\" src=\"\/wp-content\/uploads\/2020\/06\/17ae36d4ca58f0347b0b17f5fcb31c7b.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\ndhe<\/p>\n<pre><code class=\"bash\">sudo nano \/etc\/suricata\/suricata.yaml<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata\" src=\"\/wp-content\/uploads\/2020\/06\/d2d39b52920aa2019fd2a3ec74fcab78.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nKujdes! Para se ta nisim, duhet t\u00eb kontrollojm\u00eb vlerat e variablave nga seksioni vars.<\/p>\n<p>P\u00ebr t\u00eb p\u00ebrfunduar konfigurimin, do t\u00eb duhet t\u00eb instalojm\u00eb suricata-update p\u00ebr t\u00eb p\u00ebrdit\u00ebsuar dhe shkarkuar rregulla. Kjo \u00ebsht\u00eb mjaft e thjesht\u00eb:<\/p>\n<pre><code class=\"bash\">sudo apt install python-pip\nsudo pip install pyyaml\nsudo pip install &lt;a href=&quot;https:\/\/github.com\/OISF\/suricata-update\/archive\/master.zip&quot;&gt;https:\/\/github.com\/OISF\/suricata-update\/archive\/master.zip&lt;\/a&gt;\nsudo pip install --pre --upgrade suricata-update<\/code><\/pre>\n<p>\nTani na nevojitet t\u00eb ekzekutojm\u00eb komand\u00ebn suricata-update p\u00ebr t\u00eb instaluar setin e rregullave Emerging Threats Open:<\/p>\n<pre><code class=\"bash\">sudo suricata-update<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata\" src=\"\/wp-content\/uploads\/2020\/06\/e3174089b6a2c67b8db36d2e40c50af9.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nP\u00ebr t\u00eb par\u00eb list\u00ebn e burimeve t\u00eb rregullave, ekzekutojm\u00eb komand\u00ebn e m\u00ebposhtme:<\/p>\n<pre><code class=\"bash\">sudo suricata-update list-sources<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata\" src=\"\/wp-content\/uploads\/2020\/06\/7cded45bf414c2c2e76fc0bb3e1bb65c.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nP\u00ebrdit\u00ebsojm\u00eb burimet e rregullave:<\/p>\n<pre><code class=\"bash\">sudo suricata-update update-sources<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata\" src=\"\/wp-content\/uploads\/2020\/06\/786f46118b87cece96e818c70662e3c4.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nRishikojm\u00eb burimet e p\u00ebrdit\u00ebsuara:<\/p>\n<pre><code class=\"bash\">sudo suricata-update list-sources<\/code><\/pre>\n<p>\nN\u00ebse \u00ebsht\u00eb e nevojshme, mund t\u00eb aktivizojm\u00eb burimet falas t\u00eb disponueshme:<\/p>\n<pre><code class=\"bash\">sudo suricata-update enable-source ptresearch\/attackdetection\nsudo suricata-update enable-source oisf\/trafficid\nsudo suricata-update enable-source sslbl\/ssl-fp-blacklist<\/code><\/pre>\n<p>\nPas k\u00ebsaj, duhet t\u00eb p\u00ebrdit\u00ebsojm\u00eb rregullat p\u00ebrs\u00ebri:<\/p>\n<pre><code class=\"bash\">sudo suricata-update<\/code><\/pre>\n<p>\nMe k\u00ebt\u00eb, instalimi dhe konfigurimi i par\u00eb i Suricata n\u00eb Ubuntu 18.04 LTS mund t\u00eb konsiderohet i p\u00ebrfunduar. Tani fillon pjesa m\u00eb interesante: n\u00eb artikullin e ardhsh\u00ebm ne do ta lidhim serverin virtual me rrjetin e zyr\u00ebs p\u00ebrmes VPN dhe do t\u00eb fillojm\u00eb t\u00eb analizojm\u00eb gjith trafikun q\u00eb vjen dhe del. Do t'i kushtojm\u00eb nj\u00eb v\u00ebmendje t\u00eb ve\u00e7ant\u00eb bllokimit t\u00eb sulmeve DDoS, aktiviteteve t\u00eb softuer\u00ebve t\u00eb d\u00ebmsh\u00ebm dhe p\u00ebrpjekjeve p\u00ebr shfryt\u00ebzimin e dob\u00ebsive n\u00eb sh\u00ebrbimet e aksesueshme nga rrjetet publike. P\u00ebr ta ilustruar k\u00ebt\u00eb, do t\u00eb simulojm\u00eb sulme t\u00eb llojeve m\u00eb t\u00eb zakonshme.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"http:\/\/ruvds.com\/ru-rub?utm_source=habr&amp;utm_medium=article&amp;utm_campaign=ek&amp;utm_content=snort-ili-suricata-2\"><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata\" src=\"\/wp-content\/uploads\/2020\/06\/8911da77f90d8843a2c0da3c1cb1d5b0.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"http:\/\/ruvds.com\/ru-rub?utm_source=habr&amp;utm_medium=article&amp;utm_campaign=ek&amp;utm_content=snort-ili-suricata-2#order\"><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata\" src=\"\/wp-content\/uploads\/2020\/06\/f9220be24979f78c539e08d755f4257f.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/507234\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0415\u0441\u043b\u0438 \u0432\u0435\u0440\u0438\u0442\u044c \u0441\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0435, \u043e\u0431\u044a\u0435\u043c \u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u043d\u0430 50% \u043a\u0430\u0436\u0434\u044b\u0439 \u0433\u043e\u0434. \u042d\u0442\u043e \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442 \u043a \u0440\u043e\u0441\u0442\u0443 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0435 \u0438, \u0432 \u0447\u0430\u0441\u0442\u043d\u043e\u0441\u0442\u0438, \u043f\u043e\u0432\u044b\u0448\u0430\u0435\u0442 \u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u044f \u043a \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438 IDS\/IPS. \u041c\u043e\u0436\u043d\u043e \u043f\u043e\u043a\u0443\u043f\u0430\u0442\u044c \u0434\u043e\u0440\u043e\u0433\u043e\u0441\u0442\u043e\u044f\u0449\u0435\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0435 \u0436\u0435\u043b\u0435\u0437\u043e, \u043d\u043e \u0435\u0441\u0442\u044c \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u043f\u043e\u0434\u0435\u0448\u0435\u0432\u043b\u0435 \u2014 \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u0435 \u043e\u0434\u043d\u043e\u0439 \u0438\u0437 \u0441\u0438\u0441\u0442\u0435\u043c \u0441 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c \u043a\u043e\u0434\u043e\u043c. \u041c\u043d\u043e\u0433\u0438\u0435 \u043d\u0430\u0447\u0438\u043d\u0430\u044e\u0449\u0438\u0435 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u044b \u0441\u0447\u0438\u0442\u0430\u044e\u0442, \u0431\u0443\u0434\u0442\u043e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438 \u0441\u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u0443\u044e IPS [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":85991,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-85990","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0415\u0441\u043b\u0438 \u0432\u0435\u0440\u0438\u0442\u044c \u0441\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0435, \u043e\u0431\u044a\u0435\u043c \u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u043d\u0430 50% \u043a\u0430\u0436\u0434\u044b\u0439 \u0433\u043e\u0434. \u042d\u0442\u043e \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442 \u043a \u0440\u043e\u0441\u0442\u0443 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0435 \u0438, \u0432 \u0447\u0430\u0441\u0442\u043d\u043e\u0441\u0442\u0438, \u043f\u043e\u0432\u044b\u0448\u0430\u0435\u0442 \u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u044f \u043a \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438 IDS\/IPS.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-2-ustanovka-i-pervichnaya-nastrojka-suricata\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Snort \u0438\u043b\u0438 Suricata. \u0427\u0430\u0441\u0442\u044c 2: \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0438 \u043f\u0435\u0440\u0432\u0438\u0447\u043d\u0430\u044f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 Suricata | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0415\u0441\u043b\u0438 \u0432\u0435\u0440\u0438\u0442\u044c \u0441\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0435, \u043e\u0431\u044a\u0435\u043c \u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u043d\u0430 50% \u043a\u0430\u0436\u0434\u044b\u0439 \u0433\u043e\u0434. \u042d\u0442\u043e \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442 \u043a \u0440\u043e\u0441\u0442\u0443 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0435 \u0438, \u0432 \u0447\u0430\u0441\u0442\u043d\u043e\u0441\u0442\u0438, \u043f\u043e\u0432\u044b\u0448\u0430\u0435\u0442 \u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u044f \u043a \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438 IDS\/IPS.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-2-ustanovka-i-pervichnaya-nastrojka-suricata\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-20T23:42:12+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-20T23:42:12+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Snort apo Suricata. Pjesa 2: Instalimi dhe konfigurimi fillestar i Suricata | ProHoster","description":"N\u00ebse i besojm\u00eb statistikave, volumi i trafikut rrjetor rritet me rreth 50% \u00e7do vit. Kjo ka si pasoj\u00eb rritjen e ngarkes\u00ebs n\u00eb pajisje dhe, n\u00eb ve\u00e7anti, rrit k\u00ebrkesat p\u00ebr performanc\u00ebn e IDS\/IPS.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-2-ustanovka-i-pervichnaya-nastrojka-suricata","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Snort \u0438\u043b\u0438 Suricata. \u0427\u0430\u0441\u0442\u044c 2: \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0438 \u043f\u0435\u0440\u0432\u0438\u0447\u043d\u0430\u044f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 Suricata | ProHoster","og:description":"\u0415\u0441\u043b\u0438 \u0432\u0435\u0440\u0438\u0442\u044c \u0441\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0435, \u043e\u0431\u044a\u0435\u043c \u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u043d\u0430 50% \u043a\u0430\u0436\u0434\u044b\u0439 \u0433\u043e\u0434. \u042d\u0442\u043e \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442 \u043a \u0440\u043e\u0441\u0442\u0443 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0435 \u0438, \u0432 \u0447\u0430\u0441\u0442\u043d\u043e\u0441\u0442\u0438, \u043f\u043e\u0432\u044b\u0448\u0430\u0435\u0442 \u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u044f \u043a \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438 IDS\/IPS.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-2-ustanovka-i-pervichnaya-nastrojka-suricata","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-20T23:42:12+00:00","article:modified_time":"2020-06-20T23:42:12+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"85990","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:26:01","updated":"2026-08-11 12:50:15","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/85990","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=85990"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/85990\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/85991"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=85990"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=85990"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=85990"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}