LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-26-2005, 01:38 PM   #1
nethunter
LQ Newbie
 
Registered: Feb 2005
Posts: 16

Rep: Reputation: 0
Unhappy Intruder detection system


Iam a student, a novice in the linux. Iam assigned the project of creating a intrusion detection system in linux. Is it possible to create it in two months for a novice like me?? where can I get the required help and papers? Plz help.
 
Old 12-26-2005, 01:45 PM   #2
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
It depends. I you want to have a professional one, like let's say Snort, it's not possible. If you want to show how it looks and works, I see no problem. IDS is a large topic, however, and you should know first what kind of IDS you want to build.
 
Old 12-26-2005, 01:50 PM   #3
nethunter
LQ Newbie
 
Registered: Feb 2005
Posts: 16

Original Poster
Rep: Reputation: 0
Well I dont need a professional one. I need that for a student project so it's enough if does the tasks like scanning da ports etc. Just the basic model will do. Any reply and help will be appreciated.
 
Old 12-26-2005, 02:02 PM   #4
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
You need to define the requirements carefully. Port scans can be detected easily (by just counting SYNs in time intervals). The biggest decision is if you want to write a signature-based one or behaviour-based one. BTW first option is easier.

Here's a link to a FAQ: http://www.sans.org/resources/idfaq/ Enough to see what's all the thing about.
 
Old 12-27-2005, 11:05 PM   #5
true_atlantis
Member
 
Registered: Oct 2003
Distribution: fedora cor 5 x86_64
Posts: 639

Rep: Reputation: 30
when you say 'create an intrusion detection system' do you mean write a IDS program, or do you mean setup an IDS? those are two totally different tasks.
 
Old 12-28-2005, 10:22 AM   #6
nethunter
LQ Newbie
 
Registered: Feb 2005
Posts: 16

Original Poster
Rep: Reputation: 0
Unhappy

I want to write a program for the intrusion detection system. I jus wanna code a simple knowledge based intrusion detection system. Where can I get some sample codes??
 
Old 12-28-2005, 01:29 PM   #7
true_atlantis
Member
 
Registered: Oct 2003
Distribution: fedora cor 5 x86_64
Posts: 639

Rep: Reputation: 30
i dont think your going to be able to find any sample codes out there... if i were you, i would set up an IDS like snort, and see how it works, to get ideas of how to implement it.
 
Old 12-28-2005, 02:37 PM   #8
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
Knowledge-based IDS is usually just a simple scanner. The hardest thing is to parse the rules it has. If you hard--code them, it's really easy. Example: 5 SYNs from one IP in less than a minute means scan. Simple, right? Choose language and the network-access library (like pcap when you decide to write in C).
 
Old 12-28-2005, 04:36 PM   #9
despotic
LQ Newbie
 
Registered: Jun 2004
Distribution: Slackware 10.1
Posts: 15

Rep: Reputation: 0
Quote:
Originally Posted by nethunter
I want to write a program for the intrusion detection system. I jus wanna code a simple knowledge based intrusion detection system. Where can I get some sample codes??
I guess this is the point of your project isn't it ... why don't you just do your homework, or ask your Prof, TA's for pointers? Geez!
 
Old 12-31-2005, 01:00 AM   #10
aq_mishu
Member
 
Registered: Sep 2005
Location: Bangladesh
Distribution: RH 7.2, 8, 9, Fedora
Posts: 217

Rep: Reputation: 30
Right... Be sure from your prof what he really wants.. a setup or a complete program.. and also what kind... Then get help from TAs and net...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
intrusion detection system aparna Linux - General 4 01-02-2006 09:30 AM
intrusion detection system aparna Linux - General 2 12-31-2005 01:03 AM
operating system detection mili General 3 06-21-2005 04:23 AM
intruder into my system? What can I do? Y0jiMb0 Linux - Security 18 01-31-2004 11:10 AM
How do you kick some intruder out? hubergeek Linux - Networking 1 04-23-2002 03:59 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration