LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-13-2010, 05:10 PM   #1
loba09
LQ Newbie
 
Registered: May 2009
Posts: 15

Rep: Reputation: 0
Smile set up IDS and Firewall


hi

i,m new in security analyst
i want set up IDS(Intrusion detection system) and Firewall in my home
just for learning..
The Goal is learn IDS log and Firewall log..

any suggestion?
any tutorial i can follow?
 
Old 02-13-2010, 07:39 PM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
Probably a skillful use of Google until you can zoom in on what you are looking for. You may find people posting in mail groups of parts of their own logs with questions on what it means. The Netfilter website may have information on analyzing the firewall log files. Defining rules for an IDS or your firewall would require knowledge on network protocols, which will help learn what the logs mean as well.
 
1 members found this post helpful.
Old 02-16-2010, 03:43 AM   #3
nowonmai
Member
 
Registered: Jun 2003
Posts: 481

Rep: Reputation: 48
Start with snort and the ruleset from http://www.emergingthreats.net/
Then read the rules! This will give you an idea what an attack looks like.
Learn how attacks are performed.
TBH, very few actual penetrations happen by random attacks... most are targeted spearphishing attacks or client side vulnerabilities.
Set up a 'honeypot' in a DMZ on your own network. Use purposely vulnerable services in this and examine the logs to see what happens when a bot attempts to penetrate.
This is not something you'll pick up overnight. You can't just learn an aspect of infosec, you need a good coherent overview.
 
Old 02-16-2010, 08:52 AM   #4
loba09
LQ Newbie
 
Registered: May 2009
Posts: 15

Original Poster
Rep: Reputation: 0
Smile

thanks guys...
 
Old 03-16-2010, 08:45 PM   #5
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
I'd skip ET (Emerging Threats) rules and rely on the rules from Snort.org, for now, at least. ET rules have NO documentation and breaking down the rules as a new person to this field can be daunting. At least Snort has better documentation and will point you to some good resources.

Also, some ET rules are robust but a good bit of them are garbage. People savvy with Snort know what's garbage and will filter those rules out. People new to the platform may be overwhelmed with rules that alert on legit traffic but have no good documentation.

Google.com will help but the best way to learn is to just jump in. I've also attended free webinars from Sourcefire and other companies...those seminars usually have subject-matter that is basic and allows for understanding (they break geek speak and terminology into layman's terms). Also, some paid software solutions offer free versions of their products (mod_security and Aanval are two)...you can use those in the home environment to learn.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IDS and Layer 7 Firewall for Linux tajamari Linux - Hardware 1 02-04-2008 11:29 AM
Linux IDS/Firewall ninjaz Linux - Networking 5 06-19-2006 01:08 PM
Need IDS if using IPtables/Firewall?? schteelhead Linux - Security 1 11-06-2004 12:28 PM
help about IDS and firewall Babba Linux - Security 2 02-11-2003 05:35 AM
GUI Firewall/IDS netmatrix0 Linux - Security 7 12-07-2002 09:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:04 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration