{"id":86501,"date":"2020-06-26T07:42:00","date_gmt":"2020-06-26T05:42:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set"},"modified":"2020-06-26T07:42:00","modified_gmt":"2020-06-26T05:42:00","slug":"snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set","title":{"rendered":"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/507234\/\">artikulli i m\u00ebparsh\u00ebm<\/a><\/noindex> Ne kemi folur se si t\u00eb lansoni nj\u00eb version stabil t\u00eb Suricata n\u00eb Ubuntu 18.04 LTS. T\u00eb konfigurosh IDS n\u00eb nj\u00eb nyje dhe t\u00eb lidh\u00ebsh paketat falas t\u00eb rregullave \u00ebsht\u00eb mjaft e leht\u00eb. Sot do t\u00eb shohim se si me an\u00eb t\u00eb Suricata t\u00eb instaluar n\u00eb nj\u00eb server virtual mund t\u00eb mbrojm\u00eb rrjetin e korporat\u00ebs nga format m\u00eb t\u00eb zakonshme t\u00eb sulmeve. P\u00ebr k\u00ebt\u00eb, na nevojitet nj\u00eb VDS mbi Linux me dy b\u00ebrthama procesori. Kapaciteti i memories RAM varet nga ngarkesa: disa njer\u00ebz mjaftojn\u00eb me 2 GB, nd\u00ebrsa p\u00ebr detyra m\u00eb serioze mund t\u00eb nevojiten 4 ose madje 6. Avantazhi i makin\u00ebs virtuale \u00ebsht\u00eb mund\u00ebsia e eksperimentimit: mund t\u00eb fillojm\u00eb me nj\u00eb konfigurim minimal dhe t\u00eb rritim burimet sipas nevoj\u00ebs.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/508052\/\"><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/27cd9ba910418444ac7a2b5482f2a8a7.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex>foto: Reuters<\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/506730\/\">Snort ose Suricata. Pjesa 1: zgjedhja e nj\u00eb IDS\/IPS falas p\u00ebr mbrojtjen e rrjetit t\u00eb kompanis\u00eb<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/507234\/\">Snort ose Suricata. Pjesa 2: instalimi dhe konfigurimi fillestar i Suricata<\/a><\/noindex><\/li>\n<\/ul>\n<p><\/p>\n<h2>Bashkimi i rrjeteve<\/h2>\n<p>\nT\u00eb transferosh IDS n\u00eb nj\u00eb makin\u00eb virtuale mund t\u00eb jet\u00eb e nevojshme kryesisht p\u00ebr teste. N\u00ebse nuk keni pasur ndonj\u00ebher\u00eb t\u00eb b\u00ebni me zgjidhje t\u00eb tilla, nuk \u00ebsht\u00eb e men\u00e7ur t\u00eb nxitojn\u00eb t\u00eb porositni harduer fizik dhe t\u00eb ndryshoni arkitektur\u00ebn e rrjetit. M\u00eb mir\u00eb ta testoni sistemin n\u00eb nj\u00eb m\u00ebnyr\u00eb t\u00eb sigurt dhe pa shpenzime t\u00eb tep\u00ebrta p\u00ebr t\u00eb p\u00ebrcaktuar nevojat p\u00ebr burimet p\u00ebrpunuese. \u00cbsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb kuptoni se t\u00eb gjith\u00eb trafiku korporativ, n\u00eb k\u00ebt\u00eb rast, do t\u00eb kaloj\u00eb p\u00ebrmes nj\u00eb nyjeje t\u00eb vetme t\u00eb jashtme: p\u00ebr t\u00eb lidhur rrjetin lokal (ose disa rrjete) me VDS-n\u00eb q\u00eb ka Suricata t\u00eb instaluar, mund t\u00eb p\u00ebrdorni <noindex><a rel=\"nofollow\" href=\"https:\/\/www.softether.org\/\">SoftEther<\/a><\/noindex> \u2014 nj\u00eb server VPN t\u00eb thjesht\u00eb p\u00ebr tu konfigurimin dhe multi-platform\u00eb q\u00eb siguron enkriptim t\u00eb besuesh\u00ebm. Lidhja zyrtare me internetin mund t\u00eb mos ket\u00eb nj\u00eb IP reale, prandaj \u00ebsht\u00eb m\u00eb mir\u00eb ta ngresh n\u00eb VPS. N\u00eb depozita t\u00eb Ubuntu nuk ka paketa t\u00eb gatshme, do t\u00eb duhet t\u00eb shkarkosh softin ose nga <noindex><a rel=\"nofollow\" href=\"https:\/\/www.softether.org\/\">faqja e projektit<\/a><\/noindex>, ose nga nj\u00eb depo e jashtme n\u00eb sh\u00ebrbimin <noindex><a rel=\"nofollow\" href=\"https:\/\/launchpad.net\/~paskal-07\/+archive\/ubuntu\/softethervpn\">Launchpad<\/a><\/noindex> (n\u00ebse i besoni asaj):<\/p>\n<pre><code class=\"bash\">sudo add-apt-repository ppa:paskal-07\/softethervpn\nsudo apt-get update<\/code><\/pre>\n<p>\nLista e paketa t\u00eb disponueshme mund t\u00eb shikohet me komand\u00ebn e m\u00ebposhtme:<\/p>\n<pre><code class=\"bash\">apt-cache search softether<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/14803c275d46c02a43a52eec9254042c.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNa nevojiten softether-vpnserver (serveri n\u00eb konfigurim testimi \u00ebsht\u00eb aktivizuar n\u00eb VDS), si dhe softether-vpncmd \u2014 utilitetet e linj\u00ebs s\u00eb komandave p\u00ebr konfigurimin e tij.<\/p>\n<pre><code class=\"bash\">sudo apt-get install softether-vpnserver softether-vpncmd<\/code><\/pre>\n<p>\nP\u00ebr konfigurimin e serverit p\u00ebrdoret nj\u00eb utilitet i ve\u00e7ant\u00eb i linj\u00ebs s\u00eb komandave:<\/p>\n<pre><code class=\"bash\">sudo vpncmd<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/39e1f66848527a771a246aaa9f163933.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNuk do t\u00eb flasim n\u00eb detaje p\u00ebr konfigurimin: procedura \u00ebsht\u00eb mjaft e thjesht\u00eb, \u00ebsht\u00eb p\u00ebrshkruar mir\u00eb n\u00eb publikime t\u00eb shumta dhe nuk \u00ebsht\u00eb e lidhur posa\u00e7\u00ebrisht me tem\u00ebn e artikullit. N\u00eb p\u00ebrmbledhje, pas fillimit t\u00eb vpncmd, duhet t\u00eb zgjidhni opsionin 1 p\u00ebr t\u00eb kaluar n\u00eb konsoll\u00ebn e menaxhimit t\u00eb serverit. P\u00ebr k\u00ebt\u00eb duhet t\u00eb shkruani emrin localhost dhe t\u00eb shtypni enter n\u00eb vend q\u00eb t\u00eb shkruani emrin e hub-it. N\u00eb konsol\u00eb, vendoset nj\u00eb fjal\u00ebkalim administrator me komand\u00ebn serverpasswordset, hiqet hub-i virtual DEFAULT (komanda hubdelete) dhe krijohet nj\u00eb i ri me emrin Suricata_VPN, si dhe vendoset fjal\u00ebkalimi i tij (komanda hubcreate). Pastaj, duhet t\u00eb kaloni n\u00eb konsol\u00ebn e menaxhimit t\u00eb hub-it t\u00eb ri me komand\u00ebn hub Suricata_VPN p\u00ebr t\u00eb krijuar nj\u00eb grup dhe nj\u00eb p\u00ebrdorues me komandat groupcreate dhe usercreate. Fjal\u00ebkalimi i p\u00ebrdoruesit caktohet me komand\u00ebn userpasswordset. <\/p>\n<p>SoftEther mb\u00ebshtet dy m\u00ebnyra t\u00eb transmetimit t\u00eb trafikut: SecureNAT dhe Local Bridge. E para \u00ebsht\u00eb nj\u00eb teknologji e firm\u00ebs p\u00ebr nd\u00ebrtimin e nj\u00eb rrjeti privat virtual me NAT dhe DHCP t\u00eb vetin. SecureNAT nuk k\u00ebrkon TUN\/TAP, as konfigurojm\u00eb Netfilter ose nj\u00eb firewall tjet\u00ebr. Rrjet\u00ebzimi nuk prek b\u00ebrtham\u00ebn e sistemit, dhe t\u00eb gjith\u00eb proceset jan\u00eb virtualizuar dhe punojn\u00eb n\u00eb \u00e7do VPS\/VDS, pavar\u00ebsisht nga hipervizori i p\u00ebrdorur. Kjo \u00e7on n\u00eb ngarkes\u00eb m\u00eb t\u00eb madhe n\u00eb procesor dhe ulje t\u00eb shpejt\u00ebsis\u00eb n\u00eb krahasim me modin Local Bridge, i cili lidh hub-in virtual t\u00eb SoftEther me nj\u00eb adaptues fizik t\u00eb rrjetit ose pajisjen TAP. <\/p>\n<p>Konfigurimi n\u00eb k\u00ebt\u00eb rast komplikohet, sepse rrjet\u00ebzimi ndodh n\u00eb nivelin e b\u00ebrtham\u00ebs me ndihm\u00ebn e Netfilter. VDS-t\u00eb tona jan\u00eb t\u00eb nd\u00ebrtuara mbi Hyper-V, prandaj n\u00eb hapin e fundit krijojm\u00eb nj\u00eb ur\u00eb lokale dhe aktivizojm\u00eb pajisjen TAP me komand\u00ebn bridgecreate Suricate_VPN -device:suricate_vpn -tap:yes. Pas daljes nga konsola e menaxhimit t\u00eb hub-it do t\u00eb shohim n\u00eb sistem nj\u00eb nd\u00ebrfaqe t\u00eb re rrjeti, s\u00eb cil\u00ebs ende nuk i \u00ebsht\u00eb caktuar nj\u00eb IP:<\/p>\n<pre><code class=\"bash\">ifconfig<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/336fc07fbb44793719789e3f3ce1f124.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nM\u00eb pas do t\u00eb duhet t\u00eb aktivizoni rrjet\u00ebzimin e paketimeve midis nd\u00ebrfaqeve (ip forward), n\u00ebse ajo nuk \u00ebsht\u00eb aktive:<\/p>\n<pre><code class=\"bash\">sudo nano \/etc\/sysctl.conf<\/code><\/pre>\n<p>\n\u00c7aktivizoni linj\u00ebn e m\u00ebposhtme:<\/p>\n<pre><code class=\"bash\">net.ipv4.ip_forward = 1<\/code><\/pre>\n<p>\nRuani ndryshimet n\u00eb skedarin, dilni nga redaktori dhe aplikoni ato me komand\u00ebn e m\u00ebposhtme:<\/p>\n<pre><code class=\"bash\">sudo sysctl -p<\/code><\/pre>\n<p>\nM\u00eb pas, na nevojitet t\u00eb caktojm\u00eb nj\u00eb subnet p\u00ebr rrjetin virtual me IP t\u00eb rreme (p.sh., 10.0.10.0\/24) dhe t'i caktojm\u00eb nj\u00eb adres\u00eb nd\u00ebrfaqes:<\/p>\n<pre><code class=\"bash\">sudo ifconfig tap_suricata_vp 10.0.10.1\/24<\/code><\/pre>\n<p>\nM\u00eb pas do t'ju duhet t\u00eb shkruani rregulla Netfilter.<\/p>\n<p>1. N\u00eb rast nevoje, lejoni paketat e ardhshme n\u00eb portet e d\u00ebgjuara (protokolli i firm\u00ebs SoftEther p\u00ebrdor HTTPS dhe portin 443)<\/p>\n<pre><code class=\"bash\">sudo iptables -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT\nsudo iptables -A INPUT -p tcp -m tcp --dport 992 -j ACCEPT\nsudo iptables -A INPUT -p tcp -m tcp --dport 1194 -j ACCEPT\nsudo iptables -A INPUT -p udp -m udp --dport 1194 -j ACCEPT\nsudo iptables -A INPUT -p tcp -m tcp --dport 5555 -j ACCEPT<\/code><\/pre>\n<p>\n2. Konfiguroni NAT nga subneti 10.0.10.0\/24 n\u00eb IP-n\u00eb kryesore t\u00eb serverit<\/p>\n<pre><code class=\"bash\">sudo iptables -t nat -A POSTROUTING -s 10.0.10.0\/24 -j SNAT --to-source 45.132.17.140<\/code><\/pre>\n<p>\n3. Lejojm\u00eb kalimin e paketave nga n\u00ebnrrjeti 10.0.10.0\/24<\/p>\n<pre><code class=\"bash\">sudo iptables -A FORWARD -s 10.0.10.0\/24 -j ACCEPT<\/code><\/pre>\n<p>\n4. Lejojm\u00eb kalimin e paketave p\u00ebr lidhjet e vendosura tashm\u00eb<\/p>\n<pre><code class=\"bash\">sudo iptables -A FORWARD -p all -m state --state ESTABLISHED,RELATED -j ACCEPT<\/code><\/pre>\n<p>\nAutomatizimin e procesit gjat\u00eb ri\u00e7eljes s\u00eb sistemit me skenar\u00eb inicializimi do ta l\u00ebm\u00eb p\u00ebr lexuesit si detyr\u00eb sht\u00ebpie. <\/p>\n<p>N\u00ebse d\u00ebshironi t\u00eb japni automatikisht IP p\u00ebr klient\u00ebt, gjithashtu duhet t\u00eb instaloni ndonj\u00eb sh\u00ebrbim DHCP p\u00ebr ur\u00ebn lokale. Me k\u00ebt\u00eb, konfigurimi i serverit \u00ebsht\u00eb p\u00ebrfunduar dhe mund t\u00eb kaloni te klient\u00ebt. SoftEther mb\u00ebshtet protokolle t\u00eb shumta, p\u00ebrdorimi i t\u00eb cilave varet nga mund\u00ebsit\u00eb e pajisjeve n\u00eb rrjetin lokal. <\/p>\n<pre><code class=\"bash\">netstat -ap |grep vpnserver<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/42511aeec204ee27b65325d296e30db3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDuke qen\u00eb se routeri yn\u00eb testues gjithashtu punon n\u00ebn Ubuntu, do t\u00eb instalojm\u00eb paketat softether-vpnclient dhe softether-vpncmd nga nj\u00eb depo t\u00eb jashtme, n\u00eb m\u00ebnyr\u00eb q\u00eb t\u00eb p\u00ebrfitojm\u00eb nga protokolli i mark\u00ebs. Ne do t\u00eb duhet t\u00eb nisnim klientin:<\/p>\n<pre><code class=\"bash\">sudo vpnclient start<\/code><\/pre>\n<p>\nP\u00ebr konfigurimin, p\u00ebrdorim mjetin vpncmd, duke zgjedhur localhost si makin\u00ebn ku \u00ebsht\u00eb nisur vpnclient. T\u00eb gjitha komandat kryhen n\u00eb konsol\u00eb: do t\u00eb duhet t\u00eb krijoni nj\u00eb nd\u00ebrfaqe virtuale (NicCreate) dhe nj\u00eb llogari (AccountCreate). <\/p>\n<p>N\u00eb disa raste \u00ebsht\u00eb e nevojshme t\u00eb caktosh metod\u00ebn e autentikimit me komanda si AccountAnonymousSet, AccountPasswordSet, AccountCertSet dhe AccountSecureCertSet. Duke qen\u00eb se nuk p\u00ebrdorim DHCP, adresa p\u00ebr adaptern virtual duhet t\u00eb caktohet manualisht. <\/p>\n<p>P\u00ebrve\u00e7 k\u00ebsaj, do t\u00eb na duhet t\u00eb aktivizojm\u00eb ip forward (parametri net.ipv4.ip_forward=1 n\u00eb skedarin \/etc\/sysctl.conf) dhe t\u00eb konfiguroni rrug\u00ebt statike. N\u00ebse \u00ebsht\u00eb e nevojshme, n\u00eb VDS me Suricata mund t\u00eb konfigurohet kalimi i porteve p\u00ebr p\u00ebrdorimin e sh\u00ebrbimeve t\u00eb instaluara n\u00eb rrjetin lokal. Me k\u00ebt\u00eb, bashkimi i rrjeteve mund t\u00eb quhet i p\u00ebrfunduar.<\/p>\n<p>Konfigurimi q\u00eb propozojm\u00eb do t\u00eb duket k\u00ebshtu:<\/p>\n<p><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/8c650da06420efd25cbb6ed71f37aac2.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h2>Konfigurojm\u00eb Suricata<\/h2>\n<p>\nN\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/507234\/\">artikulli i m\u00ebparsh\u00ebm<\/a><\/noindex> kemi folur p\u00ebr dy modet e funksionimit t\u00eb IDS: p\u00ebrmes radh\u00ebs NFQUEUE (modi NFQ) dhe p\u00ebrmes zero copy (modi AF_PACKET). I dyti k\u00ebrkon dy nd\u00ebrfaqe, por ofron performanc\u00eb m\u00eb t\u00eb lart\u00eb \u2014 ne do ta p\u00ebrdorim pik\u00ebrisht k\u00ebt\u00eb. Parametri \u00ebsht\u00eb caktuar si i zakonsh\u00ebm n\u00eb \/etc\/default\/suricata. Gjithashtu, do t\u00eb na duhet t\u00eb redaktojm\u00eb seksionin vars n\u00eb \/etc\/suricata\/suricata.yaml, duke e p\u00ebrcaktuar atje n\u00ebnrrjetin virtual si sht\u00ebpin\u00eb.<\/p>\n<p><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/b3dc856ba0436de16fbd2ed0f1fa70a9.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nP\u00ebr t\u00eb ri\u00e7elur IDS p\u00ebrdorim komand\u00ebn:<\/p>\n<pre><code class=\"bash\">systemctl restart suricata<\/code><\/pre>\n<p>\nZgjidhja \u00ebsht\u00eb gati, tani mund t\u00eb nevojitet t\u00eb kontrolloni q\u00ebndrueshm\u00ebrin\u00eb e saj ndaj veprimeve t\u00eb sulmuesve.<\/p>\n<h2>Simulojm\u00eb sulmet<\/h2>\n<p>\nKa disa skenar\u00eb p\u00ebr p\u00ebrdorimin e sh\u00ebrbimit t\u00eb jasht\u00ebm IDS:<\/p>\n<p><b>Mbrojtja nga sulmet DDoS (q\u00ebllimi kryesor)<\/b><\/p>\n<p>Realizimi i nj\u00eb varianti t\u00eb till\u00eb brenda rrjetit korporativ \u00ebsht\u00eb i v\u00ebshtir\u00eb, pasi paketat p\u00ebr analiz\u00eb duhet t\u00eb kalojn\u00eb n\u00eb nd\u00ebrfaqen e sistemit q\u00eb shikon n\u00eb internet. Edhe n\u00ebse IDS i blokon, trafik i pad\u00ebshiruar mund ta bllokoj\u00eb kanalin e transmetimit t\u00eb t\u00eb dh\u00ebnave. P\u00ebr ta shmangur k\u00ebt\u00eb, nevojitet t\u00eb porositni nj\u00eb VPS me nj\u00eb lidhje interneti mjaft t\u00eb fuqishme, n\u00eb gjendje t\u00eb kaloj\u00eb t\u00eb gjith\u00eb trafikun e rrjetit lokal dhe gjith\u00eb trafikun e jasht\u00ebm. Kjo shpesh \u00ebsht\u00eb m\u00eb e thjesht\u00eb dhe m\u00eb e lir\u00eb se sa t\u00eb zgjeroni kanalin e zyr\u00ebs. Si nj\u00eb alternativ\u00eb, p\u00ebrmendim sh\u00ebrbime t\u00eb specializuara p\u00ebr mbrojtje nga DDoS. Kostoja e sh\u00ebrbimeve t\u00eb tyre \u00ebsht\u00eb e ngjashme me koston e nj\u00eb serveri virtual, por nuk k\u00ebrkohet konfigurim i lodhsh\u00ebm, megjithat\u00eb ka edhe disavantazhe \u2014 p\u00ebr parat\u00eb e saj, klienti merr vet\u00ebm mbrojtjen nga DDoS, nd\u00ebrsa IDS e vet \u00ebsht\u00eb e konfigurueshme si d\u00ebshiron.<\/p>\n<p><b>Mbrojtja nga sulmet e jashtme t\u00eb tipeve t\u00eb tjera<\/b> <\/p>\n<p>Suricata \u00ebsht\u00eb n\u00eb gjendje t\u00eb p\u00ebrballoj\u00eb p\u00ebrpjekjet p\u00ebr shp exploitation t\u00eb dob\u00ebsive t\u00eb ndryshme n\u00eb sh\u00ebrbimet e aksesueshme nga interneti n\u00eb rrjetin korporativ (server\u00ebt e post\u00ebs elektronike, server\u00ebt web dhe aplikacionet web etj.). Zakonisht, p\u00ebr k\u00ebt\u00eb IDS instalohet brenda rrjetit lokal pas pajisjeve kufizuese, por edhe d\u00ebrgimi i saj jasht\u00eb \u00ebsht\u00eb i ligjsh\u00ebm.<\/p>\n<p><b>Mbrojtja nga keqb\u00ebr\u00ebsit e brendsh\u00ebm<\/b><\/p>\n<p>Pavar\u00ebsisht t\u00eb gjitha p\u00ebrpjekjeve t\u00eb administratorit t\u00eb sistemit, kompjuter\u00ebt n\u00eb rrjetin korporativ mund t\u00eb infektohen nga malware. P\u00ebr m\u00eb tep\u00ebr, ndonj\u00ebher\u00eb shfaqen huligan\u00eb q\u00eb p\u00ebrpiqen t\u00eb kryejn\u00eb disa operacione t\u00eb paligjshme. Suricata \u00ebsht\u00eb n\u00eb gjendje t\u00eb ndihmoj\u00eb p\u00ebr t\u00eb bllokuar k\u00ebto p\u00ebrpjekje, megjithat\u00eb p\u00ebr mbrojtjen e rrjetit t\u00eb brendsh\u00ebm \u00ebsht\u00eb m\u00eb mir\u00eb t\u00eb instalohet brenda perimetrit dhe t\u00eb p\u00ebrdoret n\u00eb \u00e7ift me nj\u00eb switch menaxher q\u00eb mund t\u00eb mbaj\u00eb trafik n\u00eb nj\u00eb port. Nj\u00eb IDS e jashtme n\u00eb k\u00ebt\u00eb rast gjithashtu nuk \u00ebsht\u00eb aspak e padobishme \u2014 t\u00eb pakt\u00ebn ajo mund t\u00eb kap\u00eb p\u00ebrpjekjet e malware q\u00eb jetojn\u00eb n\u00eb LAN p\u00ebr t'u lidhur me nj\u00eb server t\u00eb jasht\u00ebm.<\/p>\n<p>S\u00eb pari do t\u00eb krijojm\u00eb nj\u00eb VPS testues tjet\u00ebr sulmues, dhe n\u00eb routerin e rrjetit lokal do t\u00eb ngrem\u00eb Apache me konfigurimin e parazgjedhur, pas t\u00eb cilit do ta kalojm\u00eb portin 80 nga serveri IDS. M\u00eb pas do t\u00eb imitojm\u00eb nj\u00eb sulm DDoS nga nodi sulmues. P\u00ebr k\u00ebt\u00eb do t\u00eb shkarkojm\u00eb nga GitHub, do ta kompilohet dhe do ta nisim n\u00eb nodin sulmues nj\u00eb program t\u00eb vog\u00ebl xerxes (mund t\u00eb nevojitet instalimi i paket\u00ebs gcc):<\/p>\n<pre><code class=\"bash\">git clone https:\/\/github.com\/Soldie\/xerxes-DDos-zanyarjamal-C.git\ncd xerxes-DDos-zanyarjamal-C\/\ngcc xerxes.c -o xerxes \n.\/xerxes 45.132.17.140 80<\/code><\/pre>\n<p>\nRezultati i pun\u00ebs s\u00eb saj ishte si n\u00eb vijim:<\/p>\n<p><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/80fe4d74ae71cfb16c91336102479670.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSuricata ndalon sulmuesin, nd\u00ebrsa faqja e Apache-it n\u00eb parazgjedhje hapet, pavar\u00ebsisht nga sulmi yn\u00eb improvizues dhe nj\u00eb kanal mjaft t\u00eb dob\u00ebt \"zyrtar\" (n\u00eb t\u00eb v\u00ebrtet\u00eb sht\u00ebpiak). P\u00ebr detyra m\u00eb serioze, \u00ebsht\u00eb mir\u00eb t\u00eb p\u00ebrdoret <noindex><a rel=\"nofollow\" href=\"https:\/\/www.metasploit.com\/\">Metasploit Framework<\/a><\/noindex>. Ai \u00ebsht\u00eb i destinuar p\u00ebr t\u00eb kryer teste penetrimi dhe lejon imitim t\u00eb sulmeve t\u00eb ndryshme. Udh\u00ebzimi p\u00ebr instalim <noindex><a rel=\"nofollow\" href=\"https:\/\/www.metasploit.com\/get-started\">e disponueshme<\/a><\/noindex> \u00ebsht\u00eb n\u00eb faqen e projektit. Pas instalimit, do t\u00eb nevojitet nj\u00eb p\u00ebrdit\u00ebsim:<\/p>\n<pre><code class=\"bash\">sudo msfupdate<\/code><\/pre>\n<p>\nP\u00ebr testim, nisni msfconsole.<\/p>\n<p><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/b2a08cf048ae726ca720e942729ed7f8.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nFatkeq\u00ebsisht, n\u00eb versionet e fundit t\u00eb k\u00ebtij framework-u nuk ka mund\u00ebsi p\u00ebr thyerjen automatike, k\u00ebshtu q\u00eb eksploit\u00ebt do t\u00eb duhet t\u00eb renditen manualisht dhe t\u00eb nisen me komand\u00ebn use. S\u00eb pari, \u00ebsht\u00eb mir\u00eb t\u00eb p\u00ebrcaktohen portet e hapura n\u00eb makin\u00ebn e sulmuar, p\u00ebr shembull, duke p\u00ebrdorur nmap (n\u00eb rastin ton\u00eb, netstat n\u00eb nodin e sulmuar \u00ebsht\u00eb mjaft e p\u00ebrshtatshme), dhe m\u00eb pas t\u00eb zgjidhen dhe p\u00ebrdoren modulet e p\u00ebrshtatshme t\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.rapid7.com\/db\/\">Metasploit<\/a><\/noindex>.\u00a0<\/p>\n<p>Ekzistojn\u00eb dhe mjete t\u00eb tjera p\u00ebr t\u00eb kontrolluar q\u00ebndrueshm\u00ebrin\u00eb e IDS ndaj sulmeve, duke p\u00ebrfshir\u00eb sh\u00ebrbime online. P\u00ebr kuriozitet, mund t\u00eb zhvilloni testimin e stresit p\u00ebrmes nj\u00eb versioni prov\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ipstresser.com\/\">IP Stresser<\/a><\/noindex>. P\u00ebr t\u00eb kontrolluar reagimin ndaj veprimeve t\u00eb keqb\u00ebr\u00ebsve t\u00eb brendsh\u00ebm, \u00ebsht\u00eb mir\u00eb t\u00eb instaloni mjete speciale n\u00eb nj\u00eb nga makinat e rrjetit lokal. Ka shum\u00eb mund\u00ebsi dhe \u00ebsht\u00eb mir\u00eb q\u00eb her\u00eb pas here t\u2019i aplikoni jo vet\u00ebm n\u00eb poligonin eksperimental, por edhe n\u00eb sistemet e pun\u00ebs, por kjo \u00ebsht\u00eb nj\u00eb histori krejt tjet\u00ebr.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"http:\/\/ruvds.com\/ru-rub?utm_source=habr&amp;utm_medium=article&amp;utm_campaign=ek&amp;utm_content=snort-ili-suricata-3\"><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/801a7d4e4fa0aa755205509bd2d26020.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"http:\/\/ruvds.com\/ru-rub?utm_source=habr&amp;utm_medium=article&amp;utm_campaign=ek&amp;utm_content=snort-ili-suricata-3#order\"><img decoding=\"async\" alt=\"Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit t\u00eb zyr\u00ebs\" src=\"\/wp-content\/uploads\/2020\/06\/e2c2a9e30fae35d3a3afaea1915dc106.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ruvds\/blog\/508052\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e Suricata \u0432 Ubuntu 18.04 LTS. \u041d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c IDS \u043d\u0430 \u043e\u0434\u043d\u043e\u043c \u0443\u0437\u043b\u0435 \u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u044b\u0435 \u043d\u0430\u0431\u043e\u0440\u044b \u043f\u0440\u0430\u0432\u0438\u043b \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u043d\u0435\u0441\u043b\u043e\u0436\u043d\u043e. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0440\u0430\u0437\u0431\u0435\u0440\u0435\u043c\u0441\u044f, \u043a\u0430\u043a \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 Suricata \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u0443\u044e \u0441\u0435\u0442\u044c \u043e\u043d \u043d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043d\u044b\u0445 \u0432\u0438\u0434\u043e\u0432 \u0430\u0442\u0430\u043a. \u0414\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u043d\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f VDS \u043d\u0430 Linux \u0441 \u0434\u0432\u0443\u043c\u044f \u0432\u044b\u0447\u0438\u0441\u043b\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u043c\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":86502,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-86501","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e Suricata \u0432 Ubuntu 18.04 LTS.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Snort \u0438\u043b\u0438 Suricata. \u0427\u0430\u0441\u0442\u044c 3: \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c \u043e\u0444\u0438\u0441\u043d\u0443\u044e \u0441\u0435\u0442\u044c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e Suricata \u0432 Ubuntu 18.04 LTS.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-26T05:42:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-26T05:42:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Snort ose Suricata. Pjesa 3: mbrojtja e rrjetit zyrtar | ProHoster","description":"N\u00eb artikullin e kaluar ne treguam se si t\u00eb aktivizoni nj\u00eb version t\u00eb q\u00ebndruesh\u00ebm t\u00eb Suricata n\u00eb Ubuntu 18.04 LTS.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Snort \u0438\u043b\u0438 Suricata. \u0427\u0430\u0441\u0442\u044c 3: \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c \u043e\u0444\u0438\u0441\u043d\u0443\u044e \u0441\u0435\u0442\u044c | ProHoster","og:description":"\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e Suricata \u0432 Ubuntu 18.04 LTS.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/snort-ili-suricata-chast-3-zashhishhaem-ofisnuyu-set","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-26T05:42:00+00:00","article:modified_time":"2020-06-26T05:42:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"86501","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 13:00:11","updated":"2026-08-11 12:50:14","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/86501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=86501"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/86501\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/86502"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=86501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=86501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=86501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}