![]() |
![]() |
#1 |
If I May
"Chris Halsall"
Sep 2002
Barbados
101001010100002 Posts |
![]()
Since I'm often asked for advice on tools to use for network and compute reliability and security, I'd thought I'd write up something quickly here that I could refer people to.
Often a combination of different solutions is brought to bear, depending on the level of risk involved. Also, these are just some of the many (many!) tools available. Everything listed here is also Open Source; I want to be able to audit any code running such an important role. I'm going to start with just monitoring... These tools are often run on dedicated, independent, and highly secured LAMP stacks (sometimes going as far as being redundant). This way a minimalist software stack can be configured, lowering the attack surface. 1. Cacti Leverages on RRDtool to collect, store and graph long-term time-domain data. Useful for trending analysis and NOC/SOC/CSIRT/etc real-time "eyes on glass". 2. Nagios Similar, but is more oriented to real-time situational awareness. Can generate alerts to wake up humans in the case the NOC isn't 24/7/365. The "Nagios Core" is Open Source. Additional front-end functionality can be added for a license fee. 3. Syslog Built into all Linux systems. Highly advised to have an aggregating Syslog server receiving and analyzing log files. Ideally real-time, but also possibly forensically. 4. Fail2ban Actually should be running on all servers (with /var/log/fail2ban.log forwarded to the Syslog aggregation server(s)). Can easily be configured to block (and report) unwanted behavior. Can even be used to rate-limit web services to abusive users over long temporal periods. 5. tcpdump When things get "interesting"... There's nothing like sniffing the wire in real-time (and the console output reminds some of the Matrix...)! Also, writing traffic to a file for post-analysis by Wireshark can be useful in long-term debugging. More to come over time. Feedback on this subject domain is welcome. Last fiddled with by chalsall on 2022-03-21 at 21:03 Reason: s/log-term/long-term/; # Sigh... |
![]() |
![]() |
![]() |
#2 | |
Feb 2017
Nowhere
589410 Posts |
![]()
How timely! Biden warns US companies of potential Russian cyberattacks
Quote:
|
|
![]() |
![]() |
![]() |
#3 | |
If I May
"Chris Halsall"
Sep 2002
Barbados
101001010100002 Posts |
![]() Quote:
I didn't understand why everyone was freaking out yesterday. I am demonstrably sometimes rather slow. |
|
![]() |
![]() |
![]() |
#4 | |
Feb 2017
Nowhere
2·7·421 Posts |
![]() Quote:
They have been failing to act for years. But that kind of "slow" might more properly be called "negligence." Especially if their failure to act results in something bad happening... |
|
![]() |
![]() |
![]() |
#5 |
If I May
"Chris Halsall"
Sep 2002
Barbados
101001010100002 Posts |
![]() |
![]() |
![]() |
![]() |
#6 | ||
Feb 2017
Nowhere
134068 Posts |
![]() Quote:
Quote:
|
||
![]() |
![]() |
![]() |
#7 |
If I May
"Chris Halsall"
Sep 2002
Barbados
24·661 Posts |
![]() |
![]() |
![]() |
![]() |
#8 |
6809 > 6502
"""""""""""""""""""
Aug 2003
101ร103 Posts
2×13×409 Posts |
![]() |
![]() |
![]() |
![]() |
#9 | |
If I May
"Chris Halsall"
Sep 2002
Barbados
24×661 Posts |
![]() Quote:
For those who aren't aware, SCADA is rather important. But almost no one knows about it. Serous infrastructure should (obviously) be very carefully managed. But, often, aren't. IMHO, air-gapping the network is just the beginning of managing the risk. The movie is amusing. But... This could actually happen. Last fiddled with by chalsall on 2022-03-24 at 01:27 Reason: Redundant language removed. |
|
![]() |
![]() |
![]() |
#10 |
Bamboozled!
"๐บ๐๐ท๐ท๐ญ"
May 2003
Down not across
2·5,711 Posts |
![]()
Kali Linux is one of the best collections of security software IMO.
Last fiddled with by xilman on 2022-03-24 at 10:37 Reason: Fix URL |
![]() |
![]() |
![]() |
#11 | |
Sep 2002
Database er0rr
22·1,063 Posts |
![]() Quote:
![]() Last fiddled with by paulunderwood on 2022-03-24 at 10:49 |
|
![]() |
![]() |
![]() |
Thread Tools | |
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
some tools for weights computing... | Thomas11 | Riesel Prime Search | 28 | 2021-07-31 04:22 |
Moderator Tools | storm5510 | Forum Feedback | 2 | 2020-05-07 15:48 |
Comparison of NFS tools | CRGreathouse | Factoring | 3 | 2018-02-05 14:55 |
Benchmark of current tools | Romuald | Factoring | 1 | 2016-11-13 10:59 |
Murphy's Law and other tools | Uncwilly | Lounge | 5 | 2014-07-07 22:36 |