¿ù°£ Àα⠰Խù°

°Ô½Ã¹° 160°Ç
   
[SNORT] Configure preprocessors
±Û¾´ÀÌ : ÃÖ°í°ü¸®ÀÚ ³¯Â¥ : 2010-06-22 (È­) 10:56 Á¶È¸ : 7226
±ÛÁÖ¼Ò :
                          

1. Configure preprocessors
ÇÁ·ÎÇÁ·Î¼¼¼­ ¼³Á¤Àº »ç¿ëÀÚ°¡ snort ¿¡ Áö¿øµÇ´Â ¿©·¯°¡Áö plugin ¸¦ ½±°Ô »ç¿ëÇÒ¼ö ÀÖµµ·Ï ÇÑ´Ù.
¼³Á¤ Çü½ÄÀº ´ÙÀ½°ú °°´Ù.

----------------------------------------------------------
preprocessor <name_of_processor>: <configuration_options>
----------------------------------------------------------

preprocessor ·Î´Â ´ÙÀ½°ú °°´Ù.

Minfrag
-------
minfrag ´Â ¾ÆÁÖ ÀÛ°Ô Á¶°¢³­ ÆÐŶÀ» ŽÁöÇÏ´Â ¿ªÈ°À» ÇÑ´Ù.
°ø°ÝÀڴ ħÀÔŽÁö ÅøÀ» ÇÇÇϱâ À§Çؼ­ ÆÐŶÀ» Àß°Ô Àß°Ô ÂÉ°Ô¼­ º¸³»±âµµ Çϴµ¥ ÀÌ·¸°Ô µÇ¸é Á¶°¢³­ ÆÐŶ¿¡ ´ëÇØ ÆÐÅϰ˻縦 Çϱ⠶§¹®¿¡ Á¤È®ÇÑ °Ë»ç¸¦ ÇÒ¼ö ¾ø´Ù. ±×·¯¹Ç·Î ¸î ¹ÙÀÌÆ® ¹Ì¸¸ÀÇ ÆÐŶÀÌ µé¾î¿À¸é °æ°í¸¦ ÇØÁÖ°Ô µÈ´Ù.

»ç¿ë¹æ¹ý : preprocessor minfrag:128 //128byte ÀÌÇÏÀÇ ÆÐŶÀº °æ°í.

Defrag
------
defrag preprocessor ´Â Á¶°¢µÈ ÆÐŶÀ» °æ°íÇÏ´Â minfrag ¿Í´Â ´Þ¸® À̸¦ °¨Áö ÇÏ°í IP ÆÐŶÀ» ÀçÁ¶ÇÕ ÇÑ´Ù. minfrag º¸´Ù´Â °­·ÂÇÑ Å½Áö¸¦ ÇÒ¼ö ÀÖ´Ù. ÇÏÁö¸¸ À̸¦ »ç¿ëÇÒ °æ¿ì ½Ã½ºÅÛ¿¡ ¸¹Àº ºÎÇÏ°¡ °É·Á Àü¼Û·®ÀÌ ¸¹Àº ³×Æ®¿÷¿¡¼­´Â ÁÖÀǸ¦ ÇØ¾ß ÇÒ°ÍÀÌ´Ù.

»ç¿ë¹æ¹ý : preprocessor defrag // ¿É¼Ç ¾øÀ½

Stream
------
stream Àº TCP stream À» ÀçÁ¶ÇÕÇÏ¿© ŽÁöÀ²À» ³ôÀδÙ. ÇÏÁö¸¸ ÀÌ°Í¿ª½Ã ¸¹Àº ½Ã½ºÅÛ ºÎÇϸ¦ ÀÏÀ¸Å°°Ô µÈ´Ù. ÅÚ³ÝÀ̳ª ftp, web Á¤µµÀÇ ¼­ºñ½º¸¦ ÇÏ´Â port Á¤µµ¸¦ Á¶ÇÕÇϸé ÁÁÀ»°Å °°´Ù.
±×¸®°í  stream À» »ç¿ëÇÒ¶§ ÁÖÀÇÇÒÁ¡ÀÌ Çϳª ÀÖ´Ù. ¼³Á¤ À§Ä¡ Àε¥... stream preprocessor ´Â ¹Ýµå½Ã defrag µÚ¿¡ , http_decode º¸´Ù´Â ¾Õ¿¡ ¼³Á¤ÀÌ µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.

»ç¿ë¹æ¹ý : preprocessor stream2: timeout 10, ports 21 23,  maxbytes 16384

timeout : ÃÊ´ÜÀ§·Î ÆÐŶÀÌ ¾øÀ»¶§ stream À» ¾ó¸¶°£ °è¼ÓÇÒ°ÍÀÎÁö °áÁ¤
port : Á¶ÇÕÇÒ ÆÐŶÀÌ µé¾î ¿À´Â port
maxbytes ´Â ÆÐŶÀ» ÀçÁ¶ÇÕÇÒ ÃÖ´ë Å©±â¸¦ ¸»ÇÑ´Ù.

HTTP Decode
------------
http_decode ´Â HTTP URL ¹®ÀÚ¿­ÀÌ ¾Ë¾Æº¸Áö ¸øÇÏ°Ô µÇÀÖ´Â °æ¿ì ±×°ÍÀ» snort ¿£Áø¿¡¼­ ¾Ë¾Æº¼¼ö ÀÖ´Â ¹®ÀÚ¿­·Î º¯È¯.

»ç¿ë¹æ¹ý : preprocessor http_decode: 80 -unicode -cginull

Portscan
---------
Portscan °ø°ÝÀ» ŽÁöÇÏ°í ·Î±×¸¦ ³²±â°Ô µÈ´Ù.

»ç¿ë¹æ¹ý: preprocessor portscan: $HOME_NET 4 3 portscan.log

Portscan Ignorehosts
---------------------
portscan detector °¡ ÀÛµ¿ÇÏÁö ¾Ê¾Æ¾ß ÇÒ IP ¸®½ºÆ®¸¦ ÁöÁ¤ÇÒ¼ö ÀÖ´Ù.

»ç¿ë¹æ¹ý: portscan-ignorehosts: <host list>


2. Config output plugins
ÆÐŶ °¨½Ã °á°ú¸¦ Ãâ·ÂÇÒ¶§ »ç¿ëµÇ´Â plugins À» ÁöÁ¤ÇÏ´Â °ÍÀÌ´Ù.
°¢ plugin ¸¶´Ù..Ãâ·ÂÇÏ´Â °¢°¢ÀÇ Ãâ·ÂÇüŸ¦ °¡Áö°í Àֱ⿡ ¾î¶²½ÄÀ¸·Î Ãâ·ÂÀ» ÇÒ°ÍÀÎÁö¸¦ ÀÌ°÷¿¡¼­ °áÁ¤ÇÏ¸é µÈ´Ù.
»ç¿ëµÇ´Â plugin module Á¾·ù´Â ´ÙÀ½°ú °°´Ù.

Alert_syslog : alert ¸¦ syslog ·Î º¸³» ¹ö¸°´Ù.

Alert_fast : alert ·Î±×¸¦ ³²±æ¶§ output file ÀÌ ÇѶóÀÎÀ¸·Î ³²±â±â ¶§¹®¿¡ ¹«Ã´ ºü¸£´Ù.

Alert_full : alert ·Î±×¸¦ ³²±æ¶§ output file ¿¡ ¸ðµç ·Î±×¸¦ ³²±â±â ¶§¹®¿¡ »ó´çÈ÷ ´À¸®´Ù.

Alert_smb : alert ¸¦ ÁÙ¶§ WinPopup Çü½ÄÀ¸·Î netbios ¸¦ »ç¿ëÇÏ´Â ¿ø°Ý ¸Ó½Å¿¡ °æ°í¸¦ ³¯·Á ÁØ´Ù.

Alert_unixsock : Unix domain socketÀ» ¼³Ä¡Çؼ­ ÀÌ°÷À¸·Î alert¸¦ ÁØ´Ù.

log_tcpdump : log packets ¸¦ tcpdump ÇüÅ·Π¹Ù²Ù¾î outfile À» ³²±ä´Ù.

database : snort ÀÇ data ¸¦ mysql,postgresql µîÀ¸·Î ÀúÀåÇÑ´Ù.

Alert_smb : alert ¸¦ ÁÙ¶§ WinPopup Çü½ÄÀ¸·Î netbios ¸¦ »ç¿ëÇÏ´Â ¿ø°Ý¸Ó½Å¿¡ °æ°í¸¦ ³¯·Á ÁØ´Ù.

Alert_unixsock : Unix domain socketÀ» ¼³Ä¡Çؼ­ ÀÌ°÷À¸·Î alert¸¦ ÁØ´Ù.

log_tcpdump : log packets ¸¦ tcpdump ÇüÅ·Π¹Ù²Ù¾î outfile À» ³²±ä´Ù.

database : snort ÀÇ data ¸¦ mysql,postgresql µîÀ¸·Î ÀúÀåÇÑ´Ù.


3. Rule set config

Snort Rule set ¼³Á¤ÆÄÀÏÀ» snort.conf ÆÄÀÏ¿¡¼­ include ¸¦ ÀÌ¿ëÇؼ­ °¡Á® ¿Â´Ù.
include xxxxxxx.rules

ÁÖÀÇ ÇÒÁ¡Àº c ¾ð¾î¿Í °°ÀÌ include ¹® ¸¶Áö¸·¿¡ ; ¸¦ »ç¿ëÇÏÁö ¾Ê´Â´Ù.

À̸§ Æнº¿öµå
ºñ¹Ð±Û (üũÇÏ¸é ±Û¾´À̸¸ ³»¿ëÀ» È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.)
¿ÞÂÊÀÇ ±ÛÀÚ¸¦ ÀÔ·ÂÇϼ¼¿ä.
   

 



 
»çÀÌÆ®¸í : ¸ðÁö¸®³× | ´ëÇ¥ : ÀÌ°æÇö | °³ÀÎÄ¿¹Â´ÏƼ : ·©Å°´åÄÄ ¿î¿µÃ¼Á¦(OS) | °æ±âµµ ¼º³²½Ã ºÐ´ç±¸ | ÀüÀÚ¿ìÆí : mojily°ñ¹ðÀÌchonnom.com Copyright ¨Ï www.chonnom.com www.kyunghyun.net www.mojily.net. All rights reserved.