1. Configure preprocessors ÇÁ·ÎÇÁ·Î¼¼¼ ¼³Á¤Àº »ç¿ëÀÚ°¡ snort ¿¡ Áö¿øµÇ´Â ¿©·¯°¡Áö plugin ¸¦ ½±°Ô »ç¿ëÇÒ¼ö ÀÖµµ·Ï ÇÑ´Ù. ¼³Á¤ Çü½ÄÀº ´ÙÀ½°ú °°´Ù.
---------------------------------------------------------- preprocessor <name_of_processor>: <configuration_options> ----------------------------------------------------------
preprocessor ·Î´Â ´ÙÀ½°ú °°´Ù.
Minfrag ------- minfrag ´Â ¾ÆÁÖ ÀÛ°Ô Á¶°¢³ ÆÐŶÀ» ŽÁöÇÏ´Â ¿ªÈ°À» ÇÑ´Ù. °ø°ÝÀڴ ħÀÔŽÁö ÅøÀ» ÇÇÇϱâ À§Çؼ ÆÐŶÀ» Àß°Ô Àß°Ô ÂÉ°Ô¼ º¸³»±âµµ Çϴµ¥ ÀÌ·¸°Ô µÇ¸é Á¶°¢³ ÆÐŶ¿¡ ´ëÇØ ÆÐÅϰ˻縦 Çϱ⠶§¹®¿¡ Á¤È®ÇÑ °Ë»ç¸¦ ÇÒ¼ö ¾ø´Ù. ±×·¯¹Ç·Î ¸î ¹ÙÀÌÆ® ¹Ì¸¸ÀÇ ÆÐŶÀÌ µé¾î¿À¸é °æ°í¸¦ ÇØÁÖ°Ô µÈ´Ù.
»ç¿ë¹æ¹ý : preprocessor minfrag:128 //128byte ÀÌÇÏÀÇ ÆÐŶÀº °æ°í.
Defrag ------ defrag preprocessor ´Â Á¶°¢µÈ ÆÐŶÀ» °æ°íÇÏ´Â minfrag ¿Í´Â ´Þ¸® À̸¦ °¨Áö ÇÏ°í IP ÆÐŶÀ» ÀçÁ¶ÇÕ ÇÑ´Ù. minfrag º¸´Ù´Â °·ÂÇÑ Å½Áö¸¦ ÇÒ¼ö ÀÖ´Ù. ÇÏÁö¸¸ À̸¦ »ç¿ëÇÒ °æ¿ì ½Ã½ºÅÛ¿¡ ¸¹Àº ºÎÇÏ°¡ °É·Á Àü¼Û·®ÀÌ ¸¹Àº ³×Æ®¿÷¿¡¼´Â ÁÖÀǸ¦ ÇØ¾ß ÇÒ°ÍÀÌ´Ù.
»ç¿ë¹æ¹ý : preprocessor defrag // ¿É¼Ç ¾øÀ½
Stream ------ stream Àº TCP stream À» ÀçÁ¶ÇÕÇÏ¿© ŽÁöÀ²À» ³ôÀδÙ. ÇÏÁö¸¸ ÀÌ°Í¿ª½Ã ¸¹Àº ½Ã½ºÅÛ ºÎÇϸ¦ ÀÏÀ¸Å°°Ô µÈ´Ù. ÅÚ³ÝÀ̳ª ftp, web Á¤µµÀÇ ¼ºñ½º¸¦ ÇÏ´Â port Á¤µµ¸¦ Á¶ÇÕÇϸé ÁÁÀ»°Å °°´Ù. ±×¸®°í stream À» »ç¿ëÇÒ¶§ ÁÖÀÇÇÒÁ¡ÀÌ Çϳª ÀÖ´Ù. ¼³Á¤ À§Ä¡ Àε¥... stream preprocessor ´Â ¹Ýµå½Ã defrag µÚ¿¡ , http_decode º¸´Ù´Â ¾Õ¿¡ ¼³Á¤ÀÌ µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.
»ç¿ë¹æ¹ý : preprocessor stream2: timeout 10, ports 21 23, maxbytes 16384
timeout : ÃÊ´ÜÀ§·Î ÆÐŶÀÌ ¾øÀ»¶§ stream À» ¾ó¸¶°£ °è¼ÓÇÒ°ÍÀÎÁö °áÁ¤ port : Á¶ÇÕÇÒ ÆÐŶÀÌ µé¾î ¿À´Â port maxbytes ´Â ÆÐŶÀ» ÀçÁ¶ÇÕÇÒ ÃÖ´ë Å©±â¸¦ ¸»ÇÑ´Ù.
HTTP Decode ------------ http_decode ´Â HTTP URL ¹®ÀÚ¿ÀÌ ¾Ë¾Æº¸Áö ¸øÇÏ°Ô µÇÀÖ´Â °æ¿ì ±×°ÍÀ» snort ¿£Áø¿¡¼ ¾Ë¾Æº¼¼ö ÀÖ´Â ¹®ÀÚ¿·Î º¯È¯.
»ç¿ë¹æ¹ý : preprocessor http_decode: 80 -unicode -cginull
Portscan --------- Portscan °ø°ÝÀ» ŽÁöÇÏ°í ·Î±×¸¦ ³²±â°Ô µÈ´Ù.
»ç¿ë¹æ¹ý: preprocessor portscan: $HOME_NET 4 3 portscan.log
Portscan Ignorehosts --------------------- portscan detector °¡ ÀÛµ¿ÇÏÁö ¾Ê¾Æ¾ß ÇÒ IP ¸®½ºÆ®¸¦ ÁöÁ¤ÇÒ¼ö ÀÖ´Ù.
»ç¿ë¹æ¹ý: portscan-ignorehosts: <host list>
2. Config output plugins ÆÐŶ °¨½Ã °á°ú¸¦ Ãâ·ÂÇÒ¶§ »ç¿ëµÇ´Â plugins À» ÁöÁ¤ÇÏ´Â °ÍÀÌ´Ù. °¢ plugin ¸¶´Ù..Ãâ·ÂÇÏ´Â °¢°¢ÀÇ Ãâ·ÂÇüŸ¦ °¡Áö°í Àֱ⿡ ¾î¶²½ÄÀ¸·Î Ãâ·ÂÀ» ÇÒ°ÍÀÎÁö¸¦ ÀÌ°÷¿¡¼ °áÁ¤ÇÏ¸é µÈ´Ù. »ç¿ëµÇ´Â plugin module Á¾·ù´Â ´ÙÀ½°ú °°´Ù.
Alert_syslog : alert ¸¦ syslog ·Î º¸³» ¹ö¸°´Ù.
Alert_fast : alert ·Î±×¸¦ ³²±æ¶§ output file ÀÌ ÇѶóÀÎÀ¸·Î ³²±â±â ¶§¹®¿¡ ¹«Ã´ ºü¸£´Ù.
Alert_full : alert ·Î±×¸¦ ³²±æ¶§ output file ¿¡ ¸ðµç ·Î±×¸¦ ³²±â±â ¶§¹®¿¡ »ó´çÈ÷ ´À¸®´Ù.
Alert_smb : alert ¸¦ ÁÙ¶§ WinPopup Çü½ÄÀ¸·Î netbios ¸¦ »ç¿ëÇÏ´Â ¿ø°Ý ¸Ó½Å¿¡ °æ°í¸¦ ³¯·Á ÁØ´Ù.
Alert_unixsock : Unix domain socketÀ» ¼³Ä¡Çؼ ÀÌ°÷À¸·Î alert¸¦ ÁØ´Ù.
log_tcpdump : log packets ¸¦ tcpdump ÇüÅ·Π¹Ù²Ù¾î outfile À» ³²±ä´Ù.
database : snort ÀÇ data ¸¦ mysql,postgresql µîÀ¸·Î ÀúÀåÇÑ´Ù.
Alert_smb : alert ¸¦ ÁÙ¶§ WinPopup Çü½ÄÀ¸·Î netbios ¸¦ »ç¿ëÇÏ´Â ¿ø°Ý¸Ó½Å¿¡ °æ°í¸¦ ³¯·Á ÁØ´Ù.
Alert_unixsock : Unix domain socketÀ» ¼³Ä¡Çؼ ÀÌ°÷À¸·Î alert¸¦ ÁØ´Ù.
log_tcpdump : log packets ¸¦ tcpdump ÇüÅ·Π¹Ù²Ù¾î outfile À» ³²±ä´Ù.
database : snort ÀÇ data ¸¦ mysql,postgresql µîÀ¸·Î ÀúÀåÇÑ´Ù.
3. Rule set config Snort Rule set ¼³Á¤ÆÄÀÏÀ» snort.conf ÆÄÀÏ¿¡¼ include ¸¦ ÀÌ¿ëÇؼ °¡Á® ¿Â´Ù. include xxxxxxx.rules
ÁÖÀÇ ÇÒÁ¡Àº c ¾ð¾î¿Í °°ÀÌ include ¹® ¸¶Áö¸·¿¡ ; ¸¦ »ç¿ëÇÏÁö ¾Ê´Â´Ù.
|