
Pulled Pork for Snort और Suricata नियम प्रबंधन (Google Code से)
Snort और Suricata नियम प्रबंधन के लिए PulledPork (Google code से)
हमसे Libera.Chat (IRC) पर जुड़ें #pulledpork
कॉपीराइट (C) 2009-2021 JJ Cummings, Michael Shirk और PulledPork टीम!
PulledPork का उपयोग करने के लिए धन्यवाद! यह फ़ाइल PulledPork के उपयोग पर कुछ बुनियादी मार्गदर्शन प्रदान करती है। कृपया इस फ़ाइल को अच्छी तरह से पढ़ें ताकि आप कुछ भी नज़रअंदाज़ न करें!
Usage: pulledpork.pl [-dEgklnRTPVvv? -help] -c <config filename> -o <rule output path>
-O <oinkcode> -s <so_rule output directory> -D <Distro> -S <SnortVer>
-p <path to your snort binary> -C <path to your snort.conf> -t <sostub output path>
-h <changelog path> -H <signal_name> -I (security|connectivity|balanced) -i <path to disablesid.conf>
-b <path to dropsid.conf> -e <path to enablesid.conf> -M <path to modifysid.conf>
-r <path to docs folder> -K <directory for separate rules files>
Options:
-help/? Print this help info.
-b Where the dropsid config file lives.
-C Path to your snort.conf
-c Where the pulledpork config file lives.
-d Do not verify signature of rules tarball, i.e. downloading fron non VRT or ET locations.
-D What Distro are you running on, for the so_rules
For latest supported options see http://www.snort.org/snort-rules/shared-object-rules
Valid Distro Types:
Alpine-3-10
Centos-6, Centos-7, Centos-8
Debian-8, Debian-9, Debian-10
FC-27, FC-30
FreeBSD-11, FreeBSD-12
OpenBSD-6-2, OpenBSD-6-4, OpenBSD-6-5
OpenSUSE-15-0, OpenSUS-15-1, OpenSUSE-42-3
RHEL-6, RHEL-7, RHEL-8
Slackware-14-2
Ubuntu-14-4, Ubuntu-16-4, Ubuntu-17-10, Ubuntu-18-4
-e Where the enablesid config file lives.
-E Write ONLY the enabled rules to the output files.
-g grabonly (download tarball rule file(s) and do NOT process)
-h path to the sid_changelog if you want to keep one?
-H Send signal_name to the pids listed in the config file (SIGHUP or SIGUSR2)
-I Specify a base ruleset( -I security,connectivity,or balanced, see README.RULESET)
-i Where the disablesid config file lives.
-k Keep the rules in separate files (using same file names as found when reading)
-K Where (what directory) do you want me to put the separate rules files?
-l Log Important Info to Syslog (Errors, Successful run etc, all items logged as WARN or higher)
-L Where do you want me to read your local.rules for inclusion in sid-msg.map
-m where do you want me to put the sid-msg.map file?
-M where the modifysid config file lives.
-n Do everything other than download of new files (disablesid, etc)
-o Where do you want me to put generic rules file?
-O Define the oinkcode on the command line (necessary for some users)
-p Path to your Snort binary
-P Process rules even if no new rules were downloaded
-R When processing enablesid, return the rules to their ORIGINAL state
-r Where do you want me to put the reference docs (xxxx.txt)
-S What version of snort are you using (2.8.6 or 2.9.0) are valid values
-s Where do you want me to put the so_rules?
-T Process text based rules files only, i.e. DO NOT process so_rules
-u Where do you want me to pull the rules tarball from
** E.g., ET, Snort.org. See pulledpork config rule_url option for value ideas
-V Print Version and exit
-v Verbose mode, you know.. for troubleshooting and such nonsense.
-vv EXTRA Verbose mode, you know.. for in-depth troubleshooting and other such nonsense.
-w Skip the SSL verification (if there are issues pulling down rule files)
-W Where you want to work around the issue where some implementations of LWP do not work with pulledpork's proxy configuration.
PulledPork का उपयोग करने का एक सरल उदाहरण होगा अपने सभी कॉन्फ़िगरेशन निर्देशों को
PulledPork.conf फ़ाइल के अंदर निर्दिष्ट करना। विशेष रूप से न्यूनतम कार्यक्षमता के लिए, अर्थात्
कोई Shared Object नियम प्रसंस्करण नहीं, आपको कम से कम rule_file, oinkcode, temp_path, tar_path, और rule_path मान
परिभाषित करने होंगे। नीचे इसके कुछ उदाहरण दिए गए हैं।
./pulledpork.pl -o /usr/local/etc/snort/rules/ -O 12345667778523452344234234 \
-u http://www.snort.org/reg-rules/snortrules-snapshot-2973.tar.gz \
-i disablesid.conf -T -H
उपरोक्त 12345667778523452344234234 के निर्दिष्ट oinkcode का उपयोग करके snort.org से
snortrules-snapshot-2973.tar.gz tarball लाएगा और उस tarball से नियम फ़ाइलों को आउटपुट पथ
/usr/local/etc/snort/rules/ में रखेगा, जबकि -i विकल्प pulledpork को बताता है कि
disablesid.conf कहाँ स्थित है, और -T विकल्प pulledpork को बताता है कि किसी भी shared object
नियम के लिए प्रक्रिया न करें और अंतिम -H विकल्प pulledpork को बताता है कि pulledpork.conf
में परिभाषित snort pid को Hangup सिग्नल भेजें।
./pulledpork.pl -c pulledpork.conf -i disablesid.conf -T -H
पहले उदाहरण के समान लेकिन सभी विकल्प pulledpork.conf फ़ाइल में निर्दिष्ट हैं (disablesid और -H को छोड़कर)...
./pulledpork.pl -c pulledpork.conf -i disablesid.conf \
-m /usr/local/etc/snort/sid-msg.map -Hn
उपरोक्त केवल disablesid को पढ़ेगा और परिभाषित अनुसार अक्षम करेगा, फिर बिना कुछ डाउनलोड किए
sid-msg.map उत्पन्न करने के बाद Hangup सिग्नल भेजेगा। ट्यूनिंग / परिवर्तन करते समय आदि के लिए अत्यधिक उपयोगी।
अगला उदाहरण, नियमों के साथ snort inline जिन्हें हम ड्रॉप और अक्षम करना चाहते हैं, फिर sid-msg.map बनाने और
परिवर्तन जानकारी sid_changes.log में लिखने के बाद अपने डेमॉन को HUP करें!
./pulledpork.pl -c pulledpork.conf -i disablesid.conf -b dropsid.conf \
-m /usr/local/etc/snort/sid-msg.map -h /var/log/sid_changes.log -H
अगला उदाहरण, पिछले के समान लेकिन यह निर्दिष्ट करते हुए कि हम डिफ़ॉल्ट "security" आधारित नियमसेट चलाना चाहते हैं
और यह कि हम enablesid.conf में निर्दिष्ट नियमों को सक्षम करना चाहते हैं।
./pulledpork.pl -c pulledpork.conf -i disablesid.conf -b dropsid.conf \
-e enablesid.conf -m /usr/local/etc/snort/sid-msg.map \
-h /var/log/sid_changes.log -I security -H
अगला उदाहरण, पिछले के समान लेकिन यह निर्दिष्ट करते हुए कि हम -K (Keep) मूल tarball नाम रखना चाहते हैं
और उन्हें /usr/local/etc/snort/rules/ में लिखना चाहते हैं।
./pulledpork.pl -c pulledpork.conf -i disablesid.conf -b dropsid.conf \
-e enablesid.conf -m /usr/local/etc/snort/sid-msg.map \
-h /var/log/sid_changes.log -I security -H -K /usr/local/etc/snort/rules/
Suricata के उपयोगकर्ताओं के लिए, वही चरण आवश्यक हैं जहाँ आपकी स्थापना फ़ाइलें स्थित हैं, लेकिन pulledpork को नियम फ़ाइलों को प्रोसेस करने के लिए केवल इतना चाहिए कि -S फ़्लैग suricata-3.1.3 या आपके द्वारा उपयोग किए जा रहे suricata के संस्करण पर सेट हो।
./pulledpork.pl -c pulledpork.conf -S suricata-3.1.3
Pulledpork को Suricata और ET/ETPro नियमों के साथ काम करना चाहिए। हालाँकि Suricata पर चलने के लिए Talos नियमों का कोई समर्थन नहीं है।
कृपया ध्यान दें कि pulledpork डिफ़ॉल्ट रूप से इस क्रम में नियम संशोधन (सक्षम, ड्रॉप, अक्षम, संशोधित) चलाता है..
इसका मतलब है कि अक्षम नियम हमेशा प्राथमिकता लेंगे.. इस प्रकार यदि आप एक ही gid:sid को सक्षम और अक्षम कॉन्फ़िगरेशन फ़ाइलों में निर्दिष्ट करते हैं, तो वह sid अक्षम हो जाएगा.. इसे श्रेणियों के लिए भी ध्यान में रखें! हालाँकि, आप मास्टर कॉन्फ़िग फ़ाइल में state_order कीवर्ड का उपयोग करके एक अलग क्रम निर्दिष्ट कर सकते हैं।
मैं शायद बाद में और जानकारी जोड़ूंगा, --help या --? सभी रनटाइम विकल्प प्रदर्शित करेगा और pulledpork.conf काफी अच्छी तरह से एनोटेटेड है... इसलिए यदि आप इसे समझ नहीं पा रहे हैं... और अधिक प्रयास करें! और एक बार जब आप इसे समझ जाएं, तो कृपया बेझिझक अतिरिक्त readme / सहायता foo के साथ योगदान दें.. धन्यवाद!
एक ओर नोट के रूप में, मैं PulledPork के नामकरण में सहायता करने के लिए अपने दोस्त ब्रूस को शाबाशी देना चाहूंगा! "उम्मीद है कि यह उसे चुप कर देगा ;-)"