
AIEngine ist ein interaktives/programmierbares NIDS (Netzwerk-Intrusion-Detection-System) der nächsten Generation für Python/Ruby/Java/Lua und Go.
AIEngine ist eine interaktive/programmierbare Netzwerk-Intrusion-Detection-Engine der nächsten Generation mit Python/Ruby/Java/Lua- und Go-Anbindung. Sie kann ohne menschliches Eingreifen lernen und bietet DNS-Domain-Klassifizierung, Spam-Erkennung, Netzwerk-Collector, Netzwerk-Forensik und viele weitere Funktionen.
AIEngine hilft Netzwerk-/Sicherheitsexperten außerdem dabei, Datenverkehr zu identifizieren und Signaturen zu entwickeln, die in NIDS, Firewalls, Traffic-Klassifikatoren usw. eingesetzt werden können.
Die Hauptfunktionen von AIEngine sind:
Weitere Informationen findest du im Ordner docs.
Um AIEngine (reduzierte Version) zu verwenden, führe einfach die Binärdatei aiengine aus oder verwende das Python/Ruby/Java/Lua-Binding.
luis@luis-xps:~/c++/aiengine/src$ ./aiengine -h
aiengine 2.1.0
Mandatory arguments:
-I [ --input ] arg Sets the network interface ,pcap file or
directory with pcap files.
Link Layer optional arguments:
-q [ --tag ] arg Selects the tag type of the ethernet layer (vlan,mpls).
TCP optional arguments:
-t [ --tcp-flows ] arg (=32768) Sets the number of TCP flows on the pool.
UDP optional arguments:
-u [ --udp-flows ] arg (=16384) Sets the number of UDP flows on the pool.
Domain optional arguments:
-D [ --domain-file ] arg Reads domain names from file.
-B [ --domain-protocol ] arg (=dns) Protocol to plug the domain-file (dns,
ssl, http).
-S [ --matched-domain ] Shows only the domains that matches.
Regex optional arguments:
-R [ --enable-signatures ] Enables the Signature engine.
-r [ --regex ] arg (=.*) Sets the regex for evaluate agains the flows.
-c [ --flow-class ] arg (=all) Uses tcp, udp or all for matches the signature
on the flows.
-m [ --matched-flows ] Shows the flows that matchs with the regex.
-M [ --matched-packet ] Shows the packet payload that matchs with
the regex.
-C [ --continue ] Continue evaluating the regex with the
next packets of the Flow.
-j [ --reject-flows ] Rejects the flows that matchs with the
regex.
-w [ --evidence ] Generates a pcap file with the matching
regex for forensic analysis.
Frequencies optional arguments:
-F [ --enable-frequencies ] Enables the Frequency engine.
-g [ --group-by ] arg (=dst-port) Groups frequencies by src-ip,dst-ip,src-por
t and dst-port.
-f [ --flow-type ] arg (=tcp) Uses tcp or udp flows.
-L [ --enable-learner ] Enables the Learner engine.
-k [ --key-learner ] arg (=80) Sets the key for the Learner engine.
-b [ --buffer-size ] arg (=64) Sets the size of the internal buffer for
generate the regex.
-Q [ --byte-quality ] arg (=80) Sets the minimum quality for the bytes of
the generated regex.
-y [ --enable-yara ] Generates a yara signature.
Optional arguments:
-n [ --stack ] arg (=lan) Sets the network stack (lan,mobile,lan6,virtual,
oflow).
-d [ --dumpflows ] Dump the flows to stdout.
-s [ --statistics ] arg (=0) Show statistics of the network stack (5 levels).
-T [ --timeout ] arg (=180) Sets the flows timeout.
-P [ --protocol ] arg Show statistics of a specific protocol of the
network stack.
-a [ --port ] arg (=0) Sets the HTTP listenting port.
-e [ --release ] Release the caches.
-l [ --release-cache ] arg Release a specific cache.
-p [ --pstatistics ] Show statistics of the process.
-o [ --summary ] Show protocol summmary statistics
(bytes,packets,% bytes,cache miss,memory).
-h [ --help ] Show help.
-v [ --version ] Show version string.
AIEngine unterstützt sechs Arten von Network-Stacks, abhängig von der Netzwerktopologie.
StackLan (lan) Lokales Netzwerk basierend auf IPv4.
StackLanIPv6 (lan6) Lokales Netzwerk mit IPv6-Unterstützung.
StackMobile (mobile) Mobilfunknetzwerk (Gn-Schnittstelle) für IPv4.
StackVirtual (virtual) Stack für virtuelle/Cloud-Umgebungen mit VxLan und transparentem GRE.
StackOpenFlow (oflow) Stack für OpenFlow-Umgebungen.
StackMobileIPv6 (mobile6) Mobilfunknetzwerk (Gn-Schnittstelle) für IPv6.