Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I deployed it at home a few years ago - a hardware server on a mirrored switchport. Really easy to set up. And from what I hear, the multi-node setup with manager is easy, too. If you want IDS but don't have a high software budget for Cisco FirePOWER or Palo Alto or $VENDORIPS, this would be a good start.

It will still take a lot of personnel time, though. Tuning alerts is critical.



Could you use this, for instance, to detect an infected Windows host talking to a botnet? Or would that sort of connection info be lost as noise in the presumably large amount of data captured?


You could definitely use Security Onion's tools for that. The full SO distribution is a little bit overkill for that. You could run YAF ([1]) on a box attached to a mirror port to log IP headers and then periodically check it against a tracker.

NetFlow or VPC Flow Logs (in AWS) would work just as well for this also.

[1] http://tools.netsa.cert.org/yaf/index.html




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: