+ All Categories
Home > Documents > Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data...

Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data...

Date post: 04-Apr-2018
Category:
Upload: nguyenkhanh
View: 214 times
Download: 1 times
Share this document with a friend
9
& Pavel Kácha [email protected]
Transcript
Page 1: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

&

Pavel Ká[email protected]

Page 2: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Zdroje dat

- HW accelerated probes- large scale (backbone-wide) flow based monitoring (NetFlow data sources)- Honey Pots- IDS, IPS, tar pit based systems, etc.. - SNMP based monitoring

Page 3: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Warden● Komunitní přístup

– Tvá data jsou dostupná Warden komunitě– Data celé komunity jsou dostupná Tobě

● BSD licence, https://warden.cesnet.cz

Page 4: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Formát – IDEA

● JSON● Jednoduchý, rozšiřitelný formát● Jednou definované klíče a typy se ale nemění● Dokážeme rozlišit primární data, agregovaná data, korelovaná data● Definice: https://idea.cesnet.cz

Page 5: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Mentat● https://mentat.cesnet.cz

Page 6: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Mentat – reporter 

Page 7: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Spolupráce

● SABUVýměna v rámci ČR

Sdílení v rámci EU NRENů

● IHAP

● PROKI

Page 8: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Komunita

● Spravujete nějaké bezpečnostní nástroje ve své infrastruktuře?– Honeypoty– Sondy– IDS, IPS– Siem– …

● Jste správcem infrastruktury organizace a pomohou vám další informace?● Jste výzkumník a potřebujete data?● Jste student a sháníte téma na diplomku/bakalářku/semestrálku?

[email protected]

Page 9: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Děkuji za pozornost

GNU Terry Pratchett


Recommended