tools and methods for managing snort sensors in distributed environments

14
TOOLS AND METHODS FOR MANAGING SNORT SENSORS IN DISTRIBUTED ENVIRONMENTS Scott Pack, Ed Carter | May 16, 2012

Upload: chaney

Post on 22-Feb-2016

31 views

Category:

Documents


0 download

DESCRIPTION

Tools and Methods for Managing Snort Sensors in Distributed Environments. Scott Pack, Ed Carter | May 16, 2012. Ohio University. Information Security Office. Three teams Assessments, Awareness, and Business Continuity Identity and Access Management Architecture and Response - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Tools and Methods for Managing Snort Sensors in Distributed Environments

TOOLS AND METHODS FOR MANAGING SNORT SENSORS IN DISTRIBUTED

ENVIRONMENTSScott Pack, Ed Carter | May 16, 2012

Page 2: Tools and Methods for Managing Snort Sensors in Distributed Environments

Ohio University

Students 36,142Faculty/Staff 4,631Routed Subnets ~256Buildings 163Unique MAC Addresses (DHCP) last year 176,412

Page 3: Tools and Methods for Managing Snort Sensors in Distributed Environments

Information Security Office

Three teams Assessments, Awareness, and Business Continuity Identity and Access Management Architecture and Response

Security Monitoring, Forensics, Vulnerability Management, Architecture Reviews, IR, etc.

Page 4: Tools and Methods for Managing Snort Sensors in Distributed Environments

Problem

How can we monitor the network for the ‘Bad Traffic’ given analyst time and financial constraints?

Page 5: Tools and Methods for Managing Snort Sensors in Distributed Environments

Hardware

Page 6: Tools and Methods for Managing Snort Sensors in Distributed Environments

Software

RedHat Enterprise Linux Snort Cobbler Puppet Daemonlogger PulledPork

Page 7: Tools and Methods for Managing Snort Sensors in Distributed Environments
Page 8: Tools and Methods for Managing Snort Sensors in Distributed Environments

Environment

29 sensors ~1.5Gbps daily average ~5000 alerts/day 9840 Rules in Use

Page 9: Tools and Methods for Managing Snort Sensors in Distributed Environments

Monitoring

Spectrum Cacti Puppet-Dashboard

Page 10: Tools and Methods for Managing Snort Sensors in Distributed Environments
Page 11: Tools and Methods for Managing Snort Sensors in Distributed Environments

Lessons

Tuning is a nightmarish necessity. Data output requires in-depth analysis to be most

useful. Sensor location is complicated. Large up-front time investment in

research/development. Unintended network troubleshooting tool.

Page 12: Tools and Methods for Managing Snort Sensors in Distributed Environments

Future Growth

Expand out to all buildings/networks. Trigger sanctions based on IDS alerts.

Page 13: Tools and Methods for Managing Snort Sensors in Distributed Environments

Resources

Snort - http://snort.org/ Puppet - http://puppetlabs.com/ Cobbler - http://cobbler.github.com/ Cacti - http://www.cacti.net/ Daemonlogger - http://

www.snort.org/snort-downloads/additional-downloads#daemonlogger

PulledPork - http://code.google.com/p/pulledpork/

Page 14: Tools and Methods for Managing Snort Sensors in Distributed Environments

THANK YOU