+ All Categories
Home > Documents > Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran...

Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran...

Date post: 22-Dec-2015
Category:
View: 223 times
Download: 0 times
Share this document with a friend
Popular Tags:
27
Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy
Transcript
Page 1: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Log Analysis and Intrusion Detection

By

Srikrishna Gudavalli

Venkata Naga Vamsi Krishna

Ravi Kiran Yellepeddy

Page 2: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Log Analysis (Windows And linux)

What is log analysis?

Describes an event (or) process activity in detail on the system.

Examples : • user authentication event log• ftp authentication .

Page 3: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Setup for LogAnalysis

• Application Log

Specific to particular application.

eg:MS word,Windows Media Player

• Security Log

Specifically logs all the security features.

• System Log

Logs all the system related activities.

Page 4: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Linux Auditing• Sysklog

• Metalog

• LogRotater

Basic Linux Auditing

Syslogd:

Gives information about the general activities about the Kernel,Mails,Process and Remote logins.

Page 5: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Intrusion Detection Systems (IDS)

• What is an intrusion Detection System (IDS)?

Intrusion Detection Systems look for attack signatures, which are specific patterns that usually indicate malicious or suspicious intent

Example : Snort

Page 6: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Steps to setup IDS

• Installation of snort

• Creation of Snort configuration files

• Creation of rules

• Testing of rules

Page 7: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Operation of Snort

Page 8: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Using Snort in Different Scenarios

• Ping

• nmap Scan Utility

• Subseven Trojan

• Telnet

• Internet Explorer

Page 9: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

SNORT AS A SNIFFER

Page 10: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Starting snort to sniff the data on the network.

Page 11: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Pinging the server from the client and sniffing data on server by snort.

Page 12: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Traffic dump for Linux using snort

Page 13: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Output for the snort sniffed data

Page 14: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Adding preprocessor to the config files of Snort to filter port scanner.

Page 15: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Xmas scan using nmap

Page 16: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Alerts in Snort log files for Xmas Stealth activity.

Page 17: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Preprocessor to sniff Trojans activity (ettercap)

Page 18: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Creating snort config file to use detection engine

Page 19: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Starting the snort service with detection engine

Page 20: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Using Internet Explorer to detect directory traversal attack

by snort

Page 21: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Alert for the Directory Traversal attack in snort alerts file

Page 22: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Creating the rules in snort to detect the subseven Trojan

Page 23: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Adding subseven rules to config file of snort

Page 24: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Starting the snort service with new subseven rule

Page 25: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Attacking the server with subseven Trojan

Page 26: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Alert log for the subseven Trojan detection

Page 27: Log Analysis and Intrusion Detection By Srikrishna Gudavalli Venkata Naga Vamsi Krishna Ravi Kiran Yellepeddy.

Subseven Trojan scenario on Linux


Recommended