4 ms·
Can someone explain what is the use-case for this OS? Do I use it as an OS to monitor my infrastructure? Eg. I use this OS to monitor and analyze my servers,
by phantom_oracle 10y ago
Can someone explain what is the use-case for this OS?
Do I use it as an OS to monitor my infrastructure?
Eg. I use this OS to monitor and analyze my servers, containers, etc (which are running their own host/container OSes)
OR
Do I use this as an OS for my servers and my containers?
Eg. Security-Onion as the Host and Security-Onion containers on my infrastructure
It isn't quite clear from what I read/see on the landing-page.
- obituary_latte 10y agoSecurity, not infrastructure. You set it up to monitor traffic and it has tools like snort, snorby, surricata, etc. that look for bad things on your network.
- detaro 10y agoThe first. The tools that come with it are used to analyze network traffic, logs etc from other hosts, with a focus on security.
- dave2000 10y agoSo I stick this on an old laptop and connect it to a spare Ethernet port on my router?
- chronid 10y agoEssentially. Or a low-power server in your rack. :)
- andrewstuart2 10y agoIdeally you use a mirror port so that all traffic being routed also gets sent to the SecurityOnion services for automated analysis, reporting, and alerts (depending on how SO is configured).
- awqrre 10y agoWould it be efficient to create iptables rules to mirror traffic on a router that doesn't have a mirroring port?
- detaro 10y agoas andrewstuart2 mentioned, you need it to see all traffic, which doesn't happen if you just connect it to the router. If you have an ethernet connection your internet traffic goes through, you'll want to put a device in there that sends you a copy of all traffic (one simple and cheap option is a Netgear GS105E switch).
- xenophonf 10y agoYou use it to monitor network activity similar to NIDS products from vendors like Cisco or Enterasys. You'd either set up network taps or mirrored switch ports, and you'd feed the resulting network traffic to one or more Security Onion sensors. The distribution includes a variety of different intrusion detection systems, e.g., Snort, Bro, together with a few different analysis tools, e.g., Barnyard, Sguil. You'd usually tap your network core or distribution layers because they naturally aggregate traffic flowing between security domains (e.g., data center/office, intranet/extranet, public/private) and because it's generally too costly to tap all but the most critical assets at the network access layer (although switches with integrated IDS are becoming a thing).