ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 2: ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืกืขื˜ืึทืคึผ ืคื•ืŸ Suricata

ืœื•ื™ื˜ ืกื˜ืึทื˜ื™ืกื˜ื™ืง, ื“ื™ ื‘ืึทื ื“ ืคื•ืŸ ื ืขืฅ ืคืึทืจืงืขืจ ื™ื ืงืจื™ืกืึทื– ืžื™ื˜ ื•ื•ืขื’ืŸ 50% ื™ืขื“ืขืจ ื™ืึธืจ. ื“ืึธืก ืคื™ืจื˜ ืฆื• ืึท ืคืึทืจื’ืจืขืกืขืจืŸ ืื™ืŸ ื“ื™ ืžืึทืกืข ืื•ื™ืฃ ื“ื™ ื•ื™ืกืจื™ื›ื˜ ืื•ืŸ, ืกืคึผืขืฆื™ืขืœ, ื™ื ืงืจื™ืกื™ื– ื“ื™ ืคืึธืจืฉื˜ืขืœื•ื ื’ ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ ืคื•ืŸ IDS / IPS. ืื™ืจ ืงืขื ืขืŸ ืงื•ื™ืคืŸ ื˜ื™ื™ึทืขืจ ืกืคึผืขืฉืึทืœื™ื™ื–ื“ ื™ื™ึทื–ื ื•ื•ืึทืจื’, ืึธื‘ืขืจ ืขืก ืื™ื– ืึท ื˜ืฉื™ืคึผืขืจ ืึธืคึผืฆื™ืข - ื™ืžืคึผืœืึทืžืขื ื™ื ื’ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืขืคึฟืขื ืขืŸ ืžืงื•ืจ ืกื™ืกื˜ืขืžืขืŸ. ืคื™ืœืข ืึธื ื”ื™ื™ื‘ืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก ื˜ืจืึทื›ื˜ืŸ ืึทื– ื™ื ืกื˜ืึธืœื™ื ื’ ืื•ืŸ ืงืึทื ืคื™ื’ื™ืขืจ ืึท ืคืจื™ื™ IPS ืื™ื– ื’ืึทื ืฅ ืฉื•ื•ืขืจ. ืื™ืŸ ื“ืขื ืคืึทืœ ืคื•ืŸ Suricata, ื“ืึธืก ืื™ื– ื ื™ืฉื˜ ืœืขื’ืึทืžืจืข ืืžืช - ืื™ืจ ืงืขื ืขืŸ ื™ื ืกื˜ืึทืœื™ืจืŸ ืขืก ืื•ืŸ ืึธื ื”ื™ื™ื‘ืŸ ืจื™ืคึผืขืœื™ื ื’ ื ืึธืจืžืึทืœ ืื ืคืืœืŸ ืžื™ื˜ ืึท ืกื›ื•ื ืคื•ืŸ ืคืจื™ื™ ื›ึผืœืœื™ื ืื™ืŸ ืึท ื‘ื™ืกืœ ืžื™ื ื•ื˜.

ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 2: ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืกืขื˜ืึทืคึผ ืคื•ืŸ Suricata
ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 1: ื˜ืฉื•ื–ื™ื ื’ ืึท ืคืจื™ื™ IDS / IPS ืฆื• ื‘ืึทืฉื™ืฆืŸ ืื™ื™ืขืจ ืคึฟื™ืจืžืข ื ืขื˜ื•ื•ืึธืจืง

ืคืืจื•ื•ืืก ื˜ืึธืŸ ืžื™ืจ ื“ืึทืจืคึฟืŸ ืืŸ ืื ื“ืขืจ ืขืคืขื ืขืŸ IPS?

ืœืึทื ื’ ื’ืขื”ืืœื˜ืŸ ื“ื™ ืกื˜ืึทื ื“ืึทืจื˜, ืกื ืึธืจื˜ ืื™ื– ื’ืขื•ื•ืขืŸ ืื™ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ื–ื™ื ื˜ ื“ื™ ืฉืคึผืขื˜ ื ื™ื™ื ื˜ื™ื–, ืึทื–ื•ื™ ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืขืจื™ื“ื–ืฉื ืึทืœื™ ืื™ื™ืŸ-ืคืึธื“ืขื. ืื™ื‘ืขืจ ื“ื™ ื™ืึธืจืŸ, ืขืก ื”ืื˜ ืงื•ื ื” ืึทืœืข ื“ื™ ืžืึธื“ืขืจืŸ ืคึฟืขื™ึดืงื™ื™ื˜ืŸ, ืึทื–ืึท ื•ื•ื™ IPv6 ืฉื˜ื™ืฆืŸ, ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืคื•ื ืึทื ื“ืขืจืงืœื™ื™ึทื‘ืŸ ืคึผืจืึธื˜ืึธืงืึธืœืก ืื•ื™ืฃ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืžื“ืจื’ื” ืึธื“ืขืจ ืึท ื•ื ื™ื•ื•ืขืจืกืึทืœ ื“ืึทื˜ืŸ ืึทืงืกืขืก ืžืึธื“ื•ืœืข.

ื“ื™ ื™ืงืขืจื“ื™ืง ืกื ืึธืจื˜ 2.X ืžืึธื˜ืึธืจ ื’ืขืœืขืจื ื˜ ืฆื• ืึทืจื‘ืขื˜ืŸ ืžื™ื˜ ืงื™ื™ืคืœ ืงืึธืจืขืก, ืึธื‘ืขืจ ืคืืจื‘ืœื™ื‘ืŸ ืื™ื™ืŸ-ื˜ืจืขื“ื™ื“ ืื•ืŸ ืงืขืŸ ื“ืขืจื™ื‘ืขืจ ื ื™ืฉื˜ ืึธืคึผื˜ื™ืžืึทืœ ื ื•ืฆืŸ ืžืึธื“ืขืจืŸ ื™ื™ึทื–ื ื•ื•ืึทืจื’ ืคึผืœืึทื˜ืคืึธืจืžืก.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืกืึทืœื•ื•ื“ ืื™ืŸ ื“ื™ ื“ืจื™ื˜ ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืกื™ืกื˜ืขื, ืึธื‘ืขืจ ืขืก ื’ืขื ื•ืžืขืŸ ืึทื–ื•ื™ ืœืึทื ื’ ืฆื• ืฆื•ื’ืจื™ื™ื˜ืŸ ืึทื– Suricata, ื’ืขืฉืจื™ื‘ืŸ ืคึฟื•ืŸ ืงืจืึทืฆืŸ, ื’ืขืจืื˜ืŸ ืฆื• ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื•ื™ืฃ ื“ื™ ืžืึทืจืง. ืื™ืŸ 2009, ืขืก ืื ื’ืขื”ื•ื™ื‘ืŸ ืฆื• ื–ื™ื™ืŸ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ืคึผื•ื ืงื˜ ื•ื•ื™ ืึท ืžื•ืœื˜ื™-ื˜ืจืขื“ืขื“ ืื ื“ืขืจ ื‘ืจื™ืจื” ืฆื• ืกื ืึธืจื˜, ื•ื•ืึธืก ื”ืื˜ IPS ืคืึทื ื’ืงืฉืึทื ื– ืื•ื™ืก ืคื•ืŸ ื“ื™ ืงืขืกื˜ืœ. ื“ืขืจ ืงืึธื“ ืื™ื– ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื•ื ื˜ืขืจ ื“ื™ GPLv2 ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ, ืึธื‘ืขืจ ื“ื™ ืคื™ื ืึทื ืฆื™ืขืœ ืคึผืึทืจื˜ื ืขืจืก ืคื•ืŸ ื“ื™ ืคึผืจื•ื™ืขืงื˜ ื”ืึธื‘ืŸ ืึทืงืกืขืก ืฆื• ืึท ืคืืจืžืื›ื˜ ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ื“ื™ ืžืึธื˜ืึธืจ. ืขื˜ืœืขื›ืข ืคืจืื‘ืœืขืžืขืŸ ืžื™ื˜ ืกืงืึทืœืึทื‘ื™ืœื™ื˜ื™ ื–ืขื ืขืŸ ืื•ื™ืคื’ืขืฉื˜ืื ืขืŸ ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ ื“ื™ ืกื™ืกื˜ืขื, ืึธื‘ืขืจ ื–ื™ื™ ื–ืขื ืขืŸ ืจื™ื–ืึทืœื•ื•ื“ ื’ืึทื ืฅ ื’ืขืฉื•ื•ื™ื ื“.

ืคืืจื•ื•ืืก ืกื•ืจื™ืงืึทื˜ืึท?

Suricata ื”ืื˜ ืขื˜ืœืขื›ืข ืžืึทื“ื–ืฉื•ืœื– (ื•ื•ื™ ืกื ืึธืจื˜): ื›ืึทืคึผืŸ, ืึทืงื•ื•ืึทื–ื™ืฉืึทืŸ, ื“ื™ืงืึธื•ื“ื™ื ื’, ื“ื™ื˜ืขืงืฉืึทืŸ ืื•ืŸ ืจืขื–ื•ืœื˜ืึทื˜. ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ืงืึทืคึผื˜ืฉืขืจื“ ืคืึทืจืงืขืจ ื’ื™ื™ื˜ ืื™ื™ื“ืขืจ ื“ื™ืงืึธื•ื“ื™ื ื’ ืื™ืŸ ืื™ื™ืŸ ืคืึธื“ืขื, ื›ืึธื˜ืฉ ื“ืึธืก ืœืึธื•ื“ื– ื“ื™ ืกื™ืกื˜ืขื ืžืขืจ. ืื•ื™ื‘ ื ื™ื™ื˜ื™ืง, ืคึฟืขื“ืขื ืงืขื ืขืŸ ื–ื™ื™ืŸ ืฆืขื˜ื™ื™ืœื˜ ืื™ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ืื•ืŸ ืฆืขืฉื™ืงื˜ ืฆื•ื•ื™ืฉืŸ ืคึผืจืึทืกืขืกืขืจื– - Suricata ืื™ื– ื–ื™ื™ืขืจ ืึธืคึผื˜ื™ืžื™ื–ืขื“ ืคึฟืึทืจ ืกืคึผืขืฆื™ืคื™ืฉ ื™ื™ึทื–ื ื•ื•ืึทืจื’, ื›ืึธื˜ืฉ ื“ืึธืก ืื™ื– ื ื™ื˜ ืžืขืจ ืึท HOWTO ืžื“ืจื’ื” ืคึฟืึทืจ ื‘ื™ื’ื™ื ืขืจื–. ืขืก ืื™ื– ืื•ื™ืš ื›ื“ืื™ ืฆื• ื‘ืืžืขืจืงืŸ ืึทื– Suricata ื”ืื˜ ืึทื•ื•ืึทื ืกื™ืจื˜ืข ื”ื˜ื˜ืคึผ ื“ื•ืจื›ืงื•ืง ืžื›ืฉื™ืจื™ื ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ HTP ื‘ื™ื‘ืœื™ืึธื˜ืขืง. ื–ื™ื™ ืงืขื ืขืŸ ืื•ื™ืš ื–ื™ื™ืŸ ื’ืขื ื™ืฆื˜ ืฆื• ืงืœืึธืฅ ืคืึทืจืงืขืจ ืึธืŸ ื“ื™ื˜ืขืงืฉืึทืŸ. ื“ื™ ืกื™ืกื˜ืขื ืื•ื™ืš ืฉื˜ื™ืฆื˜ IPv6 ื“ื™ืงืึธื•ื“ื™ื ื’, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ IPv4-in-IPv6, IPv6-in-IPv6 ื˜ืึทื ืึทืœื– ืื•ืŸ ืื ื“ืขืจืข.

ืคืึทืจืฉื™ื“ืขื ืข ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ื™ื ื˜ืขืจืกืขืคึผื˜ ืคืึทืจืงืขืจ (NFQueue, IPFRing, LibPcap, IPFW, AF_PACKET, PF_RING), ืื•ืŸ ืื™ืŸ Unix Socket ืžืึธื“ืข ืื™ืจ ืงืขื ืขืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืึทื ืึทืœื™ื™ื– PCAP ื˜ืขืงืขืก ืงืึทืคึผื˜ืฉืขืจื“ ื“ื•ืจืš ืืŸ ืื ื“ืขืจ ืกื ื™ืคืคืขืจ. ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ื“ื™ ืžืึทื“ื–ืฉืึทืœืขืจ ืึทืจืงืึทื˜ืขืงื˜ืฉืขืจ ืคื•ืŸ Suricata ืžืื›ื˜ ืขืก ื’ืจื™ื ื’ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ื ื™ื™ึทืข ืขืœืขืžืขื ื˜ืŸ ืฆื• ื›ืึทืคึผืŸ, ื“ืขืงืึธื“ืข, ืึทื ืึทืœื™ื™ื– ืื•ืŸ ืคึผืจืึธืฆืขืก ื ืขืฅ ืคึผืึทืงื™ืฅ. ืขืก ืื™ื– ืื•ื™ืš ื•ื•ื™ื›ื˜ื™ืง ืฆื• ื˜ืึธืŸ ืึทื– ืื™ืŸ Suricata, ืคืึทืจืงืขืจ ืื™ื– ืืคื’ืขืฉื˜ืขืœื˜ ืžื™ื˜ ื“ื™ ื ืึธืจืžืึทืœ ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื ืคื™ืœื˜ืขืจ. ืื™ืŸ GNU/Linux, ืฆื•ื•ื™ื™ ืึธืคึผืฆื™ืขืก ืคึฟืึทืจ IPS ืึธืคึผืขืจืึทืฆื™ืข ื–ืขื ืขืŸ ื‘ืืจืขื›ื˜ื™ื’ื˜: ื“ื•ืจืš ื“ื™ NFQUEUE ืจื™ื™ (NFQ ืžืึธื“ืข) ืื•ืŸ ื“ื•ืจืš ื ื•ืœ ืงืึธืคึผื™ืข (AF_PACKET ืžืึธื“ืข). ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืคืึทืœ, ืึท ืคึผืึทืงืึทื˜ ื•ื•ืึธืก ืึทืจื™ื™ึทืŸ iptables ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ NFQUEUE ืจื™ื™, ื•ื•ื• ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ืคึผืจืึทืกืขืกื˜ ืื•ื™ืฃ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืžื“ืจื’ื”. Suricata ืœื•ื™ืคื˜ ืขืก ืœื•ื™ื˜ ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข ื›ึผืœืœื™ื ืื•ืŸ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ืจื™ื™ ื•ื•ืขืจื“ื™ืงื˜ืก: NF_ACCEPT, NF_DROP ืื•ืŸ NF_REPEAT. ื“ื™ ืขืจืฉื˜ืข ืฆื•ื•ื™ื™ ื–ืขื ืขืŸ ื–ื™ืš-ื™ืงืกืคึผืœืึทื ืึทื˜ืึธืจื™, ืึธื‘ืขืจ ื“ื™ ืœืขืฆื˜ืข ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืฆื™ื™ื›ืŸ ืคึผืึทืงื™ืฅ ืื•ืŸ ืฉื™ืงืŸ ื–ื™ื™ ืฆื• ื“ื™ ืึธื ื”ื™ื™ื‘ ืคื•ืŸ ื“ื™ ืงืจืึทื ื˜ ื™ืคึผื˜ืึทื‘ืœืขืก ื˜ื™ืฉ. ื“ื™ AF_PACKET ืžืึธื“ืข ืื™ื– ืคืึทืกื˜ืขืจ, ืึธื‘ืขืจ ื™ืžืคึผืึธื•ื–ืึทื– ืึท ื ื•ืžืขืจ ืคื•ืŸ ืจื™ืกื˜ืจื™ืงืฉืึทื ื– ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื: ืขืก ืžื•ื–ืŸ ื”ืึธื‘ืŸ ืฆื•ื•ื™ื™ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืื•ืŸ ืึทืจื‘ืขื˜ ื•ื•ื™ ืึท ื’ื™ื™ื˜ื•ื•ื™ื™. ื“ื™ ืืคื’ืขืฉื˜ืขืœื˜ ืคึผืึทืงืึทื˜ ืื™ื– ืคืฉื•ื˜ ื ื™ืฉื˜ ืคืึธืจื•ื•ืขืจื“ื™ื“ ืฆื• ื“ื™ ืจื’ืข ืฆื•ื‘ื™ื ื“.

ืึท ื•ื•ื™ื›ื˜ื™ืง ืฉื˜ืจื™ืš ืคื•ืŸ Suricata ืื™ื– ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ื•ื•ืขืœืึทืคึผืžืึทื ืฅ ืคึฟืึทืจ ืกื ืึธืจื˜. ื“ืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื”ืื˜ ืึทืงืกืขืก ืฆื•, ืกืคึผืขืฆื™ืขืœ, ื“ื™ Sourcefire VRT ืื•ืŸ OpenSource Emerging Threats ื”ืขืจืฉืŸ ืฉื˜ืขืœื˜, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ ื’ืขืฉืขืคื˜ Emerging Threats Pro. ื“ื™ ื™ื•ื ืึทืคื™ื™ื“ ืจืขื–ื•ืœื˜ืึทื˜ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืึทื ืึทืœื™ื™ื–ื“ ืžื™ื˜ ืคืึธืœืงืก ื‘ืึทืงืขื ื“ื–, ืื•ืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืฆื• PCAP ืื•ืŸ Syslog ืื™ื– ืื•ื™ืš ื’ืขืฉื˜ื™ืฆื˜. ืกื™ืกื˜ืขื ืกืขื˜ื˜ื™ื ื’ืก ืื•ืŸ ื›ึผืœืœื™ื ื–ืขื ืขืŸ ืกื˜ืึธืจื“ ืื™ืŸ YAML ื˜ืขืงืขืก, ื•ื•ืึธืก ื–ืขื ืขืŸ ื’ืจื™ื ื’ ืฆื• ืœื™ื™ืขื ืขืŸ ืื•ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืคึผืจืึทืกืขืกื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ. ื“ื™ ืกื•ืจื™ืงืึทื˜ืึท ืžืึธื˜ืึธืจ ืื ืขืจืงืขื ื˜ ืคื™ืœืข ืคึผืจืึธื˜ืึธืงืึธืœืก, ืึทื–ื•ื™ ื“ื™ ื›ึผืœืœื™ื ื˜ืึธืŸ ื ื™ื˜ ื“ืึทืจืคึฟืŸ ืฆื• ื–ื™ื™ืŸ ื˜ื™ื™ื“ ืฆื• ืึท ืคึผืึธืจื˜ ื ื•ืžืขืจ. ืื™ืŸ ื“ืขืจืฆื•, ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ืคืœืึธื•ื•ื‘ื™ื˜ืก ืื™ื– ืึทืงื˜ื™ื•ื•ืœื™ ืคึผืจืึทืงื˜ื™ืกื˜ ืื™ืŸ ื“ื™ ืกื•ืจื™ืงืึทื˜ืึท ื›ึผืœืœื™ื. ืฆื• ืฉืคึผื•ืจ ื˜ืจื™ื’ืขืจื™ื ื’, ืกืขืกื™ืข ื•ื•ืขืจื™ืึทื‘ืึทืœื– ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜, ื•ื•ืึธืก ืœืึธื–ืŸ ืื™ืจ ืฆื• ืฉืึทืคึฟืŸ ืื•ืŸ ืฆื•ืœื™ื™ื’ืŸ ืคืึทืจืฉื™ื“ืŸ ืงืึธื•ื ื˜ืขืจืก ืื•ืŸ ืคืœืึทื’ืก. ืคื™ืœืข IDSs ืžื™ื™ึทื›ืœ ืคืึทืจืฉื™ื“ืขื ืข TCP ืงืึทื ืขืงืฉืึทื ื– ื•ื•ื™ ื‘ืึทื–ื•ื ื“ืขืจ ืขื ื˜ื™ื˜ื™ื– ืื•ืŸ ืงืขืŸ ื ื™ืฉื˜ ื–ืขืŸ ื“ื™ ืงืฉืจ ืฆื•ื•ื™ืฉืŸ ื–ื™ื™ ืฆื• ืึธื ื•ื•ื™ื™ึทื–ืŸ ื“ื™ ืึธื ื”ื™ื™ื‘ ืคื•ืŸ ืึท ื‘ืึทืคืึทืœืŸ. Suricata ืคืจื•ื•ื•ื˜ ืฆื• ื–ืขืŸ ื“ื™ ื’ืื ืฆืข ื‘ื™ืœื“ ืื•ืŸ ืื™ืŸ ืคื™ืœืข ืงืึทืกืขืก ืื ืขืจืงืขื ื˜ ื‘ื™ื™ื–ืข ืคืึทืจืงืขืจ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื™ื‘ืขืจ ืคืึทืจืฉื™ื“ืขื ืข ืงืึทื ืขืงืฉืึทื ื–. ืžื™ืจ ืงืขื ืขืŸ ืจืขื“ืŸ ื•ื•ืขื’ืŸ ื“ื™ ืึทื“ื•ื•ืึทื ื˜ื™ื“ื–ืฉื™ื– ืคึฟืึทืจ ืึท ืœืึทื ื’ ืฆื™ื™ึทื˜; ืžื™ืจ ื•ื•ืขืœืŸ ื‘ืขืกืขืจ ื’ื™ื™ืŸ ืฆื• ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’ ืื•ืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ.

ื•ื•ื™ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ?

ืžื™ืจ ื•ื•ืขืœืŸ ื™ื ืกื˜ืึทืœื™ืจืŸ Suricata ืื•ื™ืฃ ืึท ื•ื•ื™ืจื˜ื•ืึทืœ ืกืขืจื•ื•ืขืจ ืžื™ื˜ Ubuntu 18.04 LTS. ื›ืœ ืงืึทืžืึทื ื“ื– ืžื•ื–ืŸ ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ื•ื•ื™ ืกื•ืคึผืขืจื•ืกืขืจ (ื•ื•ืึธืจืฆืœ). ื“ื™ ืžืขืจืกื˜ ื–ื™ื›ืขืจ ืึธืคึผืฆื™ืข ืื™ื– ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ืกืขืจื•ื•ืขืจ ื“ื•ืจืš SSH ื•ื•ื™ ืึท ื ืึธืจืžืึทืœ ื‘ืึทื ื™ืฆืขืจ, ืื•ืŸ ื“ืขืจื ืึธืš ื ื•ืฆืŸ ื“ื™ ืกื•ื“ืึธ ื™ื•ื˜ื™ืœืึทื˜ื™ื– ืฆื• ืขืกืงืึทืœื™ื™ื˜ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–. ืขืจืฉื˜ืขืจ ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ ืคึผืึทืงืึทื“ื–ืฉืึทื– ื•ื•ืึธืก ืžื™ืจ ื“ืึทืจืคึฟืŸ:

sudo apt -y install libpcre3 libpcre3-dev build-essential autoconf automake libtool libpcap-dev libnet1-dev libyaml-0-2 libyaml-dev zlib1g zlib1g-dev libmagic-dev libcap-ng-dev libjansson-dev pkg-config libnetfilter-queue-dev geoip-bin geoip-database geoipupdate apt-transport-https

ืงืึทื ืขืงื˜ื™ื ื’ ืึท ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™:

sudo add-apt-repository ppa:oisf/suricata-stable
sudo apt-get update

ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ ืœืขืฆื˜ืข ืกื˜ืึทื‘ื™ืœ ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹Suricata:

sudo apt-get install suricata

ืื•ื™ื‘ ื ื™ื™ื˜ื™ืง, ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืขืก, ืจื™ืคึผืœื™ื™ืกื™ื ื’ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ eth0 ืžื™ื˜ ื“ื™ ืคืึทืงื˜ื™ืฉ ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืฆื•ื‘ื™ื ื“ ืคื•ืŸ ื“ื™ ืกืขืจื•ื•ืขืจ. ืคืขืœื™ืงื™ื™ึทื˜ ืกืขื˜ื˜ื™ื ื’ืก ื–ืขื ืขืŸ ืกื˜ืึธืจื“ ืื™ืŸ ื“ื™ /etc/default/suricata ื˜ืขืงืข, ืื•ืŸ ืžื ื”ื’ ืกืขื˜ื˜ื™ื ื’ืก ื–ืขื ืขืŸ ืกื˜ืึธืจื“ ืื™ืŸ /etc/suricata/suricata.yaml. IDS ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื™ื– ืžืขืจืกื˜ื ืก ืœื™ืžื™ื˜ืขื“ ืฆื• ืขื“ื™ื˜ื™ื ื’ ื“ืขื ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข. ืขืก ื”ืื˜ ืคื™ืœืข ืคึผืึทืจืึทืžืขื˜ืขืจืก ื•ื•ืึธืก, ืื™ืŸ ื ืึธืžืขืŸ ืื•ืŸ ืฆื™ืœ, ืฆื•ื ื•ื™ืคืคืึทืœืŸ ืžื™ื˜ ื–ื™ื™ืขืจ ืึทื ืึทืœืึธื’ื•ืขืก ืคื•ืŸ ืกื ืึธืจื˜. ื“ืขืจ ืกื™ื ื˜ืึทืงืก ืื™ื– ืคื•ื ื“ืขืกื˜ื•ื•ืขื’ืŸ ื’ืึธืจ ืึทื ื“ืขืจืฉ, ืึธื‘ืขืจ ื“ื™ ื˜ืขืงืข ืื™ื– ืคื™ืœ ื’ืจื™ื ื’ืขืจ ืฆื• ืœื™ื™ืขื ืขืŸ ื•ื•ื™ Snort ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื–, ืื•ืŸ ืขืก ืื™ื– ืื•ื™ืš ื’ื•ื˜ ืงืึทืžืขื ื˜ืึทื“.

sudo nano /etc/default/suricata

ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 2: ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืกืขื˜ืึทืคึผ ืคื•ืŸ Suricata

ะธ

sudo nano /etc/suricata/suricata.yaml

ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 2: ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืกืขื˜ืึทืคึผ ืคื•ืŸ Suricata

ื•ืคืžืขืจืงื–ืึทืžืงื™ื™ึทื˜! ืื™ื™ื“ืขืจ ืื™ืจ ืึธื ื”ื™ื™ื‘ืŸ, ืื™ืจ ื–ืึธืœ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื•ื•ืึทืœื•ืขืก ืคื•ืŸ ื“ื™ ื•ื•ืขืจื™ืึทื‘ืึทืœื– ืคื•ืŸ ื“ื™ ื•ื•ืึทืจืก ืึธืคึผื˜ื™ื™ืœื•ื ื’.

ืฆื• ืคืึทืจืขื ื“ื™ืงืŸ ื“ื™ ืกืขื˜ืึทืคึผ, ืื™ืจ ื•ื•ืขื˜ ื“ืึทืจืคึฟืŸ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ ืกืจื™ืงืึทื˜ืึท-ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืฆื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืื•ืŸ ืืจืืคืงืืคื™ืข ื“ื™ ื›ึผืœืœื™ื. ื“ืึธืก ืื™ื– ื’ืึทื ืฅ ื’ืจื™ื ื’ ืฆื• ื˜ืึธืŸ:

sudo apt install python-pip
sudo pip install pyyaml
sudo pip install <a href="https://github.com/OISF/suricata-update/archive/master.zip">https://github.com/OISF/suricata-update/archive/master.zip</a>
sudo pip install --pre --upgrade suricata-update

ื•ื•ื™ื™ึทื˜ืขืจ ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืœื•ื™ืคืŸ ื“ื™ ืกืขืจื™ืงืึทื˜ืึท-ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื‘ืึทืคึฟืขืœ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ ื™ืžืขืจื“ื–ืฉื™ื ื’ ื˜ืจืขืฅ ืขืคึฟืŸ ืจื•ืœืขืก:

sudo suricata-update

ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 2: ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืกืขื˜ืึทืคึผ ืคื•ืŸ Suricata

ืฆื• ื–ืขืŸ ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ื”ืขืจืฉืŸ ืงื•ื•ืืœืŸ, ืœื•ื™ืคืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ืึทืคึฟืขืœ:

sudo suricata-update list-sources

ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 2: ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืกืขื˜ืึทืคึผ ืคื•ืŸ Suricata

ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื”ืขืจืฉืŸ ืงื•ื•ืืœืŸ:

sudo suricata-update update-sources

ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 2: ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืกืขื˜ืึทืคึผ ืคื•ืŸ Suricata

ืžื™ืจ ืงื•ืงืŸ ื•ื•ื™ื“ืขืจ ืื™ืŸ ื“ื™ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืžืงื•ืจื™ื:

sudo suricata-update list-sources

ืื•ื™ื‘ ื ื™ื™ื˜ื™ืง, ืื™ืจ ืงืขื ืขืŸ ืึทืจื™ื™ึทื ื ืขืžืขืŸ ื‘ื ื™ืžืฆื ืคืจื™ื™ ืงื•ื•ืืœืŸ:

sudo suricata-update enable-source ptresearch/attackdetection
sudo suricata-update enable-source oisf/trafficid
sudo suricata-update enable-source sslbl/ssl-fp-blacklist

ื ืึธืš ื“ืขื, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื“ื™ ื›ึผืœืœื™ื ื•ื•ื™ื“ืขืจ:

sudo suricata-update

ืื™ืŸ ื“ืขื ืคื•ื ื˜, ื“ื™ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ Suricata ืื™ืŸ Ubuntu 18.04 LTS ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขืจืขื›ื ื˜ ื•ื•ื™ ื’ืึทื ืฅ. ื“ืขืจื ืึธืš ื“ื™ ืฉืคึผืึทืก ื”ื™ื™ื‘ื˜: ืื™ืŸ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืึทืจื˜ื™ืงืœ ืžื™ืจ ื•ื•ืขืœืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืึท ื•ื•ื™ืจื˜ื•ืึทืœ ืกืขืจื•ื•ืขืจ ืฆื• ื“ื™ ืึธืคื™ืก ื ืขืฅ ื“ื•ืจืš ื•ื•ืคึผืŸ ืื•ืŸ ืึธื ื”ื™ื™ื‘ืŸ ืฆื• ืึทื ืึทืœื™ื™ื– ืึทืœืข ื™ื ืงืึทืžื™ื ื’ ืื•ืŸ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืคืึทืจืงืขืจ. ืžื™ืจ ื•ื•ืขืœืŸ ื‘ืึทืฆืึธืœืŸ ืกืคึผืขืฆื™ืขืœ ื•ืคืžืขืจืงื–ืึทืžืงื™ื™ื˜ ืฆื• ื‘ืœืึทืงื™ื ื’ DDoS ืื ืคืืœืŸ, ืžืึทืœื•ื•ืึทืจืข ืึทืงื˜ื™ื•ื•ื™ื˜ืขื˜ืŸ ืื•ืŸ ืคืจื•ื•ื•ืŸ ืฆื• ื’ื•ื•ื•ืจืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ืกืขืจื•ื•ื™ืกืขืก ืฆื•ื˜ืจื™ื˜ืœืขืš ืคึฟื•ืŸ ืฆื™ื‘ื•ืจ ื ืขื˜ื•ื•ืึธืจืงืก. ืคึฟืึทืจ ืงืœืขืจื™ื˜ื™, ืึทื˜ืึทืงืก ืคื•ืŸ ื“ื™ ืžืขืจืกื˜ ืคึผืจืึธืกื˜ ื˜ื™ื™ืคึผืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืกื™ืžื™ืึทืœื™ื™ื˜ื™ื“.

ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 2: ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืกืขื˜ืึทืคึผ ืคื•ืŸ Suricata

ืกื ืึธืจื˜ ืึธื“ืขืจ ืกื•ืจื™ืงืึทื˜ืึท. ื˜ื™ื™ืœ 2: ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืขืจืฉื˜ ืกืขื˜ืึทืคึผ ืคื•ืŸ Suricata

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’