SlideShare ist ein Scribd-Unternehmen logo
1 von 23
Downloaden Sie, um offline zu lesen
Reducing network
                 attacks with Snort
                                          cleber brandao
                                    cleber.brandao[nospam]locaweb.com.br




sexta-feira, 18 de novembro de 11
Agenda
                     • What is an IDS
                     • Types of attack
                     • Snort structure
                           •
                         How snort works
                           •
                         Preprocessors
                           •
                         Output plugins
                           •
                         Operation modes
                     • Positioning
                     • Q&A



sexta-feira, 18 de novembro de 11
What is an IDS?
              • Intrusion Detection System
              • Layer 7 analysis
              • Just a sensor
              • IPS can drop packets
              • Pattern match or behavior

sexta-feira, 18 de novembro de 11
Types of attack



sexta-feira, 18 de novembro de 11
External attacks




sexta-feira, 18 de novembro de 11
Internal attacks




sexta-feira, 18 de novembro de 11
Unstructured attacks




sexta-feira, 18 de novembro de 11
Structured attacks




sexta-feira, 18 de novembro de 11
Understanding the
                                         Snort
                     • Created in 1998 just like sniff
                     • Becomes as IDS in 1999
                     • Last version 2.9.1.2


sexta-feira, 18 de novembro de 11
How snort works




sexta-feira, 18 de novembro de 11
Preproccessors

                     • sfPortScan
                     • Frag3
                     • httpInspect


sexta-feira, 18 de novembro de 11
sfPortscan

                     • Half connection scans
                     • Decoy scans
                     • Distributed scans
                     • Port sweep scans

sexta-feira, 18 de novembro de 11
Frag3


                     • Detect anomalies in fragmented packets



sexta-feira, 18 de novembro de 11
Frag3 evasion




sexta-feira, 18 de novembro de 11
Frag3 evasion (2)




sexta-feira, 18 de novembro de 11
httpInspect


                     • HTTP normalization



sexta-feira, 18 de novembro de 11
httpInspect (sample)
                     • / = %2f
                     • . = %2e
                     •       alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS
                             $HTTP_PORTS (msg:”WEB-ATTACKS /usr/bin/id command
                             attempt”;flow:to_server,established; content:”/usr/
                             bin/id”;nocase;classtype:web-application-
                             attack;sid:1332;rev:7;)


                     • %2fusr%2fbin%2fid = bybass

sexta-feira, 18 de novembro de 11
Output plugins

                     • Databases (mysql, postgre, oracle)
                     • Syslog
                     • Pcap (tcpdump, wireshark)
                     • Unified2

sexta-feira, 18 de novembro de 11
Operation modes

                     • IDS
                     • IPS
                     • Sniffer
                     • pcaps analysis

sexta-feira, 18 de novembro de 11
Positioning

                     • Sensor (port-mirror, network tap)
                     • IPS (bridge, gateway)
                     • Internal
                     • External

sexta-feira, 18 de novembro de 11
Questions ?




sexta-feira, 18 de novembro de 11
Where to find me

                     • Freenode - #securityguys, #snort-br
                     • Security conferences
                     • Buy me a Beer ;)


sexta-feira, 18 de novembro de 11
Thank you

             • www.locaweb.com.br
             • www.snort.org.br
             • www.snort.org
             • clebeerpub.blogspot.com

sexta-feira, 18 de novembro de 11

Weitere ähnliche Inhalte

Kürzlich hochgeladen

ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docxATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx2m Assessoria
 
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docxATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx2m Assessoria
 
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docxATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx2m Assessoria
 
Boas práticas de programação com Object Calisthenics
Boas práticas de programação com Object CalisthenicsBoas práticas de programação com Object Calisthenics
Boas práticas de programação com Object CalisthenicsDanilo Pinotti
 
Padrões de Projeto: Proxy e Command com exemplo
Padrões de Projeto: Proxy e Command com exemploPadrões de Projeto: Proxy e Command com exemplo
Padrões de Projeto: Proxy e Command com exemploDanilo Pinotti
 
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docxATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx2m Assessoria
 

Kürzlich hochgeladen (6)

ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docxATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
ATIVIDADE 1 - CUSTOS DE PRODUÇÃO - 52_2024.docx
 
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docxATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
ATIVIDADE 1 - GCOM - GESTÃO DA INFORMAÇÃO - 54_2024.docx
 
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docxATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
ATIVIDADE 1 - ESTRUTURA DE DADOS II - 52_2024.docx
 
Boas práticas de programação com Object Calisthenics
Boas práticas de programação com Object CalisthenicsBoas práticas de programação com Object Calisthenics
Boas práticas de programação com Object Calisthenics
 
Padrões de Projeto: Proxy e Command com exemplo
Padrões de Projeto: Proxy e Command com exemploPadrões de Projeto: Proxy e Command com exemplo
Padrões de Projeto: Proxy e Command com exemplo
 
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docxATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
ATIVIDADE 1 - LOGÍSTICA EMPRESARIAL - 52_2024.docx
 

Empfohlen

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 

Empfohlen (20)

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 

Mitigando ataques com_snort

  • 1. Reducing network attacks with Snort cleber brandao cleber.brandao[nospam]locaweb.com.br sexta-feira, 18 de novembro de 11
  • 2. Agenda • What is an IDS • Types of attack • Snort structure • How snort works • Preprocessors • Output plugins • Operation modes • Positioning • Q&A sexta-feira, 18 de novembro de 11
  • 3. What is an IDS? • Intrusion Detection System • Layer 7 analysis • Just a sensor • IPS can drop packets • Pattern match or behavior sexta-feira, 18 de novembro de 11
  • 4. Types of attack sexta-feira, 18 de novembro de 11
  • 9. Understanding the Snort • Created in 1998 just like sniff • Becomes as IDS in 1999 • Last version 2.9.1.2 sexta-feira, 18 de novembro de 11
  • 10. How snort works sexta-feira, 18 de novembro de 11
  • 11. Preproccessors • sfPortScan • Frag3 • httpInspect sexta-feira, 18 de novembro de 11
  • 12. sfPortscan • Half connection scans • Decoy scans • Distributed scans • Port sweep scans sexta-feira, 18 de novembro de 11
  • 13. Frag3 • Detect anomalies in fragmented packets sexta-feira, 18 de novembro de 11
  • 14. Frag3 evasion sexta-feira, 18 de novembro de 11
  • 15. Frag3 evasion (2) sexta-feira, 18 de novembro de 11
  • 16. httpInspect • HTTP normalization sexta-feira, 18 de novembro de 11
  • 17. httpInspect (sample) • / = %2f • . = %2e • alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:”WEB-ATTACKS /usr/bin/id command attempt”;flow:to_server,established; content:”/usr/ bin/id”;nocase;classtype:web-application- attack;sid:1332;rev:7;) • %2fusr%2fbin%2fid = bybass sexta-feira, 18 de novembro de 11
  • 18. Output plugins • Databases (mysql, postgre, oracle) • Syslog • Pcap (tcpdump, wireshark) • Unified2 sexta-feira, 18 de novembro de 11
  • 19. Operation modes • IDS • IPS • Sniffer • pcaps analysis sexta-feira, 18 de novembro de 11
  • 20. Positioning • Sensor (port-mirror, network tap) • IPS (bridge, gateway) • Internal • External sexta-feira, 18 de novembro de 11
  • 21. Questions ? sexta-feira, 18 de novembro de 11
  • 22. Where to find me • Freenode - #securityguys, #snort-br • Security conferences • Buy me a Beer ;) sexta-feira, 18 de novembro de 11
  • 23. Thank you • www.locaweb.com.br • www.snort.org.br • www.snort.org • clebeerpub.blogspot.com sexta-feira, 18 de novembro de 11