SlideShare a Scribd company logo
Security	
  Onion	
  
Peel	
  Back	
  the	
  Layers	
  of	
  Your	
  Network	
  in	
  Minutes	
  
	
  
Doug	
  Burks	
  
What	
  is	
  Security	
  Onion?	
  
Security	
  Onion	
  is	
  a	
  Linux	
  distro	
  for	
  IDS	
  (Intrusion	
  DetecBon)	
  and	
  NSM	
  
(Network	
  Security	
  Monitoring).	
  It's	
  based	
  on	
  Ubuntu	
  and	
  contains	
  Snort,	
  
Suricata,	
  Bro,	
  Sguil,	
  Squert,	
  Snorby,	
  ELSA,	
  Xplico,	
  NetworkMiner,	
  and	
  many	
  
other	
  security	
  tools.	
  The	
  easy-­‐to-­‐use	
  Setup	
  wizard	
  allows	
  you	
  to	
  build	
  an	
  army	
  
of	
  distributed	
  sensors	
  for	
  your	
  enterprise	
  in	
  minutes!	
  
IDS	
  is	
  sub-­‐opBmal;	
  need	
  NSM	
  (mulBple	
  
data	
  types)	
  
Sguil	
  is	
  the	
  defacto	
  reference	
  
implementaBon	
  of	
  NSM	
  
Lots	
  of	
  pieces	
  in	
  the	
  Sguil	
  jigsaw	
  puzzle	
  
hUp://nsmwiki.org/images/e/ea/Sguil-­‐0.7.dfd.png	
  
Security	
  Onion:	
  
Next,	
  Next,	
  Finish	
  for	
  NSM	
  
Big	
  Onions	
  
l  Use	
  our	
  ISO	
  image	
  (based	
  on	
  Xubuntu	
  12.04	
  64-­‐bit)	
  
OR	
  
Start	
  with	
  your	
  preferred	
  flavor	
  of	
  Ubuntu	
  12.04	
  (Ubuntu,	
  Kubuntu,	
  
Lubuntu,	
  Xubuntu,	
  or	
  Ubuntu	
  Server)	
  32-­‐bit	
  or	
  64-­‐bit,	
  add	
  our	
  PPA	
  and	
  
install	
  our	
  packages	
  	
  
l  High	
  performance:	
  	
  
l  Snort/Suricata/Bro	
  running	
  on	
  PF_RING	
  
l  Netsniff-­‐ng	
  uses	
  zero-­‐copy	
  for	
  high-­‐speed	
  full-­‐packet	
  capture	
  
l  ELSA	
  (like	
  a	
  free	
  version	
  of	
  Splunk)	
  –	
  distributed	
  database	
  with	
  central	
  web	
  
interface	
  
Data	
  Types	
  
l  Alert	
  data	
  
l  NIDS	
  alerts	
  from	
  Snort/Suricata	
  
l  HIDS	
  alerts	
  from	
  OSSEC	
  
l  Asset	
  data	
  from	
  Bro	
  and	
  PRADS	
  
l  Session	
  data	
  from	
  Argus,	
  Bro,	
  and	
  PRADS	
  
l  TransacBon	
  data	
  –	
  hUp/gp/dns/ssl/other	
  logs	
  from	
  Bro	
  
l  Full	
  content	
  data	
  from	
  netsniff-­‐ng	
  
Distributed	
  Deployment	
  
	
  
	
  
Snorby	
  
Pivot	
  to	
  pcap	
  from	
  Snorby	
  
CapME	
  
Squert	
  web	
  interface	
  
Sguil	
  client	
  
Pivot	
  to	
  pcap	
  from	
  Sguil	
  
NetworkMiner	
  
There’s	
  gold	
  in	
  them	
  
thar	
  PCAPs!	
  
ELSA	
  
Pivot	
  to	
  pcap	
  from	
  ELSA	
  
Ooh…shiny…	
  
Bro	
  Flow	
  
Popular	
  Dst	
  IPs	
  
Popular	
  Dst	
  Ports	
  
Drilling	
  into	
  an	
  interesBng	
  Dst	
  Port	
  
What	
  is	
  that	
  Dst	
  Port?	
  Pivot	
  2	
  Pcap!	
  
2013:	
  The	
  Metrics	
  
l  Security	
  Onion	
  10.04	
  
37,521	
  
l  Security	
  Onion	
  12.04	
  (released	
  12/31/2012)	
  
34,290	
  from	
  SourceForge	
  
l  Security	
  Onion	
  12.04.1	
  (released	
  6/10/2013)	
  
6,380	
  from	
  Sourceforge	
  
l  Security	
  Onion	
  12.04.2	
  (released	
  7/25/2013)	
  
737	
  from	
  Sourceforge	
  
l  ???	
  From	
  BitTorrent	
  
???	
  Ubuntu/Kubuntu/Lubuntu	
  +	
  Security	
  Onion	
  PPA	
  
Where	
  do	
  we	
  go	
  now?	
  
hUp://securityonion.blogspot.com	
  	
  
	
  
Updates	
  are	
  announced	
  here	
  and	
  it	
  also	
  has	
  the	
  following	
  links:	
  
l  Download/Install	
  
l  FAQ	
  
l  Mailing	
  Lists	
  
l  IRC	
  #securityonion	
  on	
  irc.freenode.net	
  
l  @securityonion	
  

More Related Content

PPTX
Security Onion - Brief
PPTX
Security Onion Conference - 2016
PPTX
2014 Security Onion Conference
PDF
Security Onion - Introduction
PDF
Suricata
PPTX
Security onion
PPTX
BackTrack5 - Linux
Security Onion - Brief
Security Onion Conference - 2016
2014 Security Onion Conference
Security Onion - Introduction
Suricata
Security onion
BackTrack5 - Linux

What's hot (20)

PPTX
Security Onion Conference - 2015
PPT
Backtrack os 5
PDF
Security Onion: Watching for Leeks
PDF
Database Firewall with Snort
PPTX
Telehack: May the Command Line Live Forever
ODP
Introduction To Linux Security
PDF
$HOME Sweet $HOME SANSFIRE Edition
ODP
Linux Network Security
PPT
Network ssecurity toolkit
PDF
Snort-IPS-Tutorial
PPT
Linux Security
PPT
Threats, Vulnerabilities & Security measures in Linux
PPT
Unix Security
PPT
Security and Linux Security
PPT
Basic Linux Security
PPTX
Essential security for linux servers
PDF
Kali tools list with short description
PPT
Linux security-fosster-09
PDF
IoT mit Rust programmieren
Security Onion Conference - 2015
Backtrack os 5
Security Onion: Watching for Leeks
Database Firewall with Snort
Telehack: May the Command Line Live Forever
Introduction To Linux Security
$HOME Sweet $HOME SANSFIRE Edition
Linux Network Security
Network ssecurity toolkit
Snort-IPS-Tutorial
Linux Security
Threats, Vulnerabilities & Security measures in Linux
Unix Security
Security and Linux Security
Basic Linux Security
Essential security for linux servers
Kali tools list with short description
Linux security-fosster-09
IoT mit Rust programmieren
Ad

Viewers also liked (8)

PPTX
Wireless Investigations using Xplico
PPTX
Giga vue hb1 event rolling presentation-final-1
PPTX
Eyeing the Onion
PDF
Gigamon 1Q15 Investor Relations Presentation
PPTX
Detecting Malicious SSL Certificates Using Bro
PPTX
Optimizing your google local listing for search
PDF
Visibility and Automation for Enhanced Security
PPTX
Harnessing the Power of Metadata for Security
Wireless Investigations using Xplico
Giga vue hb1 event rolling presentation-final-1
Eyeing the Onion
Gigamon 1Q15 Investor Relations Presentation
Detecting Malicious SSL Certificates Using Bro
Optimizing your google local listing for search
Visibility and Automation for Enhanced Security
Harnessing the Power of Metadata for Security
Ad

Similar to Security Onion: peeling back the layers of your network in minutes (18)

PDF
Security Onion - Part 1
PDF
Securing the infrastructure using IDS
PPTX
Intro to NSM with Security Onion - AusCERT
PPTX
Security Onion
PDF
Boni Yeamin Thesis final_report.pdf
PPTX
Study And Implemenataion Of Advance Intrusion Detection And Prevention Sysyte...
PPTX
security onion
PPT
snort.ppt
PPTX
Enterprise Security Monitoring, And Log Management.
PDF
Report: Study and Implementation of Advance Intrusion Detection and Preventio...
PPT
snorteeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee.ppt
ODP
PDF
Peeling back your Network Layers with Security Onion
PDF
An analysis of Network Intrusion Detection System using SNORT
PPT
Network Intrusion Detection System Using Snort
PPTX
Intrusion detection and prevention system
PDF
IDS Research
Security Onion - Part 1
Securing the infrastructure using IDS
Intro to NSM with Security Onion - AusCERT
Security Onion
Boni Yeamin Thesis final_report.pdf
Study And Implemenataion Of Advance Intrusion Detection And Prevention Sysyte...
security onion
snort.ppt
Enterprise Security Monitoring, And Log Management.
Report: Study and Implementation of Advance Intrusion Detection and Preventio...
snorteeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee.ppt
Peeling back your Network Layers with Security Onion
An analysis of Network Intrusion Detection System using SNORT
Network Intrusion Detection System Using Snort
Intrusion detection and prevention system
IDS Research

Recently uploaded (20)

PDF
Web App vs Mobile App What Should You Build First.pdf
PDF
WOOl fibre morphology and structure.pdf for textiles
PDF
August Patch Tuesday
PDF
Mushroom cultivation and it's methods.pdf
PDF
Hindi spoken digit analysis for native and non-native speakers
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
1 - Historical Antecedents, Social Consideration.pdf
PPTX
Tartificialntelligence_presentation.pptx
PDF
Zenith AI: Advanced Artificial Intelligence
PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Hybrid model detection and classification of lung cancer
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PDF
project resource management chapter-09.pdf
PPTX
Chapter 5: Probability Theory and Statistics
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
A comparative analysis of optical character recognition models for extracting...
Web App vs Mobile App What Should You Build First.pdf
WOOl fibre morphology and structure.pdf for textiles
August Patch Tuesday
Mushroom cultivation and it's methods.pdf
Hindi spoken digit analysis for native and non-native speakers
Digital-Transformation-Roadmap-for-Companies.pptx
1 - Historical Antecedents, Social Consideration.pdf
Tartificialntelligence_presentation.pptx
Zenith AI: Advanced Artificial Intelligence
DP Operators-handbook-extract for the Mautical Institute
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
Encapsulation_ Review paper, used for researhc scholars
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Hybrid model detection and classification of lung cancer
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
project resource management chapter-09.pdf
Chapter 5: Probability Theory and Statistics
Assigned Numbers - 2025 - Bluetooth® Document
A comparative analysis of optical character recognition models for extracting...

Security Onion: peeling back the layers of your network in minutes

  • 1. Security  Onion   Peel  Back  the  Layers  of  Your  Network  in  Minutes     Doug  Burks  
  • 2. What  is  Security  Onion?   Security  Onion  is  a  Linux  distro  for  IDS  (Intrusion  DetecBon)  and  NSM   (Network  Security  Monitoring).  It's  based  on  Ubuntu  and  contains  Snort,   Suricata,  Bro,  Sguil,  Squert,  Snorby,  ELSA,  Xplico,  NetworkMiner,  and  many   other  security  tools.  The  easy-­‐to-­‐use  Setup  wizard  allows  you  to  build  an  army   of  distributed  sensors  for  your  enterprise  in  minutes!  
  • 3. IDS  is  sub-­‐opBmal;  need  NSM  (mulBple   data  types)  
  • 4. Sguil  is  the  defacto  reference   implementaBon  of  NSM  
  • 5. Lots  of  pieces  in  the  Sguil  jigsaw  puzzle   hUp://nsmwiki.org/images/e/ea/Sguil-­‐0.7.dfd.png  
  • 6. Security  Onion:   Next,  Next,  Finish  for  NSM  
  • 7. Big  Onions   l  Use  our  ISO  image  (based  on  Xubuntu  12.04  64-­‐bit)   OR   Start  with  your  preferred  flavor  of  Ubuntu  12.04  (Ubuntu,  Kubuntu,   Lubuntu,  Xubuntu,  or  Ubuntu  Server)  32-­‐bit  or  64-­‐bit,  add  our  PPA  and   install  our  packages     l  High  performance:     l  Snort/Suricata/Bro  running  on  PF_RING   l  Netsniff-­‐ng  uses  zero-­‐copy  for  high-­‐speed  full-­‐packet  capture   l  ELSA  (like  a  free  version  of  Splunk)  –  distributed  database  with  central  web   interface  
  • 8. Data  Types   l  Alert  data   l  NIDS  alerts  from  Snort/Suricata   l  HIDS  alerts  from  OSSEC   l  Asset  data  from  Bro  and  PRADS   l  Session  data  from  Argus,  Bro,  and  PRADS   l  TransacBon  data  –  hUp/gp/dns/ssl/other  logs  from  Bro   l  Full  content  data  from  netsniff-­‐ng  
  • 11. Pivot  to  pcap  from  Snorby  
  • 15. Pivot  to  pcap  from  Sguil  
  • 16. NetworkMiner   There’s  gold  in  them   thar  PCAPs!  
  • 18. Pivot  to  pcap  from  ELSA  
  • 23. Drilling  into  an  interesBng  Dst  Port  
  • 24. What  is  that  Dst  Port?  Pivot  2  Pcap!  
  • 25. 2013:  The  Metrics   l  Security  Onion  10.04   37,521   l  Security  Onion  12.04  (released  12/31/2012)   34,290  from  SourceForge   l  Security  Onion  12.04.1  (released  6/10/2013)   6,380  from  Sourceforge   l  Security  Onion  12.04.2  (released  7/25/2013)   737  from  Sourceforge   l  ???  From  BitTorrent   ???  Ubuntu/Kubuntu/Lubuntu  +  Security  Onion  PPA  
  • 26. Where  do  we  go  now?   hUp://securityonion.blogspot.com       Updates  are  announced  here  and  it  also  has  the  following  links:   l  Download/Install   l  FAQ   l  Mailing  Lists   l  IRC  #securityonion  on  irc.freenode.net   l  @securityonion