pavel kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (netflow data...

9
& Pavel Kácha [email protected]

Upload: nguyenkhanh

Post on 04-Apr-2018

216 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

&

Pavel Ká[email protected]

Page 2: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Zdroje dat

- HW accelerated probes- large scale (backbone-wide) flow based monitoring (NetFlow data sources)- Honey Pots- IDS, IPS, tar pit based systems, etc.. - SNMP based monitoring

Page 3: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Warden● Komunitní přístup

– Tvá data jsou dostupná Warden komunitě– Data celé komunity jsou dostupná Tobě

● BSD licence, https://warden.cesnet.cz

Page 4: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Formát – IDEA

● JSON● Jednoduchý, rozšiřitelný formát● Jednou definované klíče a typy se ale nemění● Dokážeme rozlišit primární data, agregovaná data, korelovaná data● Definice: https://idea.cesnet.cz

Page 5: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Mentat● https://mentat.cesnet.cz

Page 6: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Mentat – reporter 

Page 7: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Spolupráce

● SABUVýměna v rámci ČR

Sdílení v rámci EU NRENů

● IHAP

● PROKI

Page 8: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Komunita

● Spravujete nějaké bezpečnostní nástroje ve své infrastruktuře?– Honeypoty– Sondy– IDS, IPS– Siem– …

● Jste správcem infrastruktury organizace a pomohou vám další informace?● Jste výzkumník a potřebujete data?● Jste student a sháníte téma na diplomku/bakalářku/semestrálku?

[email protected]

Page 9: Pavel Kácha ph@cesnet · - large scale (backbone-wide) flow based monitoring (NetFlow data sources) - Honey Pots - IDS, IPS, tar ... Intrusion Botnet/MaIware Recon Scanning Vulnerable

7. 2. 2016

Děkuji za pozornost

GNU Terry Pratchett