SURFnet distributed intrusion detection system

Who is surfnet ...

SURFnet High-qualitiy Internet for higher education and research
SURFnet connects the dutch networks of universities, colleges, research centres, academic hospitals and scientific libraries to one another and to other networks in Europe and the rest of the world.

You may want to have a look on their network structure.

SURFnet IDS facts

Below you can see first screenshots of the SURFnet IDS webinterface.
The intrusion systems structure is really sexy, surfnet ids uses openvpn to route traffic from different network ranges to a central server running nepenthes. As they had some whishes in nepenthes logging, we sat together and created a module log-surfnet that logs the attacks and details to a postgres database.

The webinterface supports usergroups, and allows each user to see how poisend his own network is compared to others.

hbarchart.jpgrank.jpg
search.jpgsensorstatus.jpg
trafficdetailed.jpg

Click the images for full size, or visit http://ids.surfnet.nl/screenshots/ for more.

short setup summary

The surfnet ids projecthomage offers more information about the setup, so some short details as a teaser

  • complete open source based
    • sensors
      • knoppix featuring openvpn
    • server
      • apache + php
      • postgres
      • nepenthes
      • rrdtool
  • setting up a sensor is easy, just plug in the knoppix usb stick and boot it, it will create the required openvpn keys and set it up by itself
  • includes webinterface to see whats going on
  • one can search for activity on ranges like “12.23.41.32/21”
  • easy to setup

Not to mention the log-surfnet nepenthes module will make it into the upcoming nepenthes release.

related links

Comments



2005/11/08/surfnet_ids.txt · Last modified: 2010/06/15 13:27 by common
chimeric.de = chi`s home Creative Commons License Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0