
Pulled Pork per la gestione delle regole di Snort e Suricata (da Google Code)
PulledPork per la gestione delle regole di Snort e Suricata (da Google code)
Trovaci su Libera.Chat (IRC) #pulledpork
Copyright (C) 2009-2021 JJ Cummings, Michael Shirk e il Team PulledPork!
Grazie per aver scelto di usare PulledPork! Questo file fornisce alcune indicazioni di base sull'uso di PulledPork. Assicurati di leggere questo file attentamente per non perdere nulla!
Usage: pulledpork.pl [-dEgklnRTPVvv? -help] -c <config filename> -o <rule output path>
-O <oinkcode> -s <so_rule output directory> -D <Distro> -S <SnortVer>
-p <path to your snort binary> -C <path to your snort.conf> -t <sostub output path>
-h <changelog path> -H <signal_name> -I (security|connectivity|balanced) -i <path to disablesid.conf>
-b <path to dropsid.conf> -e <path to enablesid.conf> -M <path to modifysid.conf>
-r <path to docs folder> -K <directory for separate rules files>
Options:
-help/? Print this help info.
-b Where the dropsid config file lives.
-C Path to your snort.conf
-c Where the pulledpork config file lives.
-d Do not verify signature of rules tarball, i.e. downloading fron non VRT or ET locations.
-D What Distro are you running on, for the so_rules
For latest supported options see http://www.snort.org/snort-rules/shared-object-rules
Valid Distro Types:
Alpine-3-10
Centos-6, Centos-7, Centos-8
Debian-8, Debian-9, Debian-10
FC-27, FC-30
FreeBSD-11, FreeBSD-12
OpenBSD-6-2, OpenBSD-6-4, OpenBSD-6-5
OpenSUSE-15-0, OpenSUS-15-1, OpenSUSE-42-3
RHEL-6, RHEL-7, RHEL-8
Slackware-14-2
Ubuntu-14-4, Ubuntu-16-4, Ubuntu-17-10, Ubuntu-18-4
-e Where the enablesid config file lives.
-E Write ONLY the enabled rules to the output files.
-g grabonly (download tarball rule file(s) and do NOT process)
-h path to the sid_changelog if you want to keep one?
-H Send signal_name to the pids listed in the config file (SIGHUP or SIGUSR2)
-I Specify a base ruleset( -I security,connectivity,or balanced, see README.RULESET)
-i Where the disablesid config file lives.
-k Keep the rules in separate files (using same file names as found when reading)
-K Where (what directory) do you want me to put the separate rules files?
-l Log Important Info to Syslog (Errors, Successful run etc, all items logged as WARN or higher)
-L Where do you want me to read your local.rules for inclusion in sid-msg.map
-m where do you want me to put the sid-msg.map file?
-M where the modifysid config file lives.
-n Do everything other than download of new files (disablesid, etc)
-o Where do you want me to put generic rules file?
-O Define the oinkcode on the command line (necessary for some users)
-p Path to your Snort binary
-P Process rules even if no new rules were downloaded
-R When processing enablesid, return the rules to their ORIGINAL state
-r Where do you want me to put the reference docs (xxxx.txt)
-S What version of snort are you using (2.8.6 or 2.9.0) are valid values
-s Where do you want me to put the so_rules?
-T Process text based rules files only, i.e. DO NOT process so_rules
-u Where do you want me to pull the rules tarball from
** E.g., ET, Snort.org. See pulledpork config rule_url option for value ideas
-V Print Version and exit
-v Verbose mode, you know.. for troubleshooting and such nonsense.
-vv EXTRA Verbose mode, you know.. for in-depth troubleshooting and other such nonsense.
-w Skip the SSL verification (if there are issues pulling down rule files)
-W Where you want to work around the issue where some implementations of LWP do not work with pulledpork's proxy configuration.
Un semplice esempio di come usare PulledPork è specificare tutte le direttive di configurazione all'interno del file PulledPork.conf. Nello specifico per una funzione minima, cioè NESSUNA elaborazione di regole Shared Object, devi definire almeno i valori rule_file, oinkcode, temp_path, tar_path e rule_path. Di seguito sono riportati alcuni esempi.
./pulledpork.pl -o /usr/local/etc/snort/rules/ -O 12345667778523452344234234 \
-u http://www.snort.org/reg-rules/snortrules-snapshot-2973.tar.gz \
-i disablesid.conf -T -H
L'esempio sopra scaricherà il tarball snortrules-snapshot-2973.tar.gz da snort.org usando l'oinkcode specificato 12345667778523452344234234 e metterà i file di regole da quel tarball nel percorso di output /usr/local/etc/snort/rules/ mentre l'opzione -i dice a pulledpork dove si trova disablesid.conf, e l'opzione -T dice a pulledpork di non elaborare regole shared object e l'opzione finale -H dice a pulledpork di inviare un segnale Hangup al pid di snort che hai definito in pulledpork.conf.
./pulledpork.pl -c pulledpork.conf -i disablesid.conf -T -H
Simile al primo esempio ma tutte le opzioni specificate nel file pulledpork.conf (tranne disablesid e -H)...
./pulledpork.pl -c pulledpork.conf -i disablesid.conf \
-m /usr/local/etc/snort/sid-msg.map -Hn
L'esempio sopra si limiterà a leggere il disablesid e disabilitare come definito, quindi invierà un segnale Hangup dopo aver generato il sid-msg.map nella posizione specificata senza scaricare nulla. Molto utile quando si mettono a punto / si apportano modifiche ecc..
Prossimo esempio, snort inline con regole che vogliamo droppare e disabilitare, quindi HUP i nostri demoni dopo aver creato un sid-msg.map e scritto le informazioni di modifica in sid_changes.log!
./pulledpork.pl -c pulledpork.conf -i disablesid.conf -b dropsid.conf \
-m /usr/local/etc/snort/sid-msg.map -h /var/log/sid_changes.log -H
Prossimo esempio, come il precedente ma specificando che vogliamo usare il ruleset predefinito "security" e che vogliamo abilitare le regole specificate in enablesid.conf.
./pulledpork.pl -c pulledpork.conf -i disablesid.conf -b dropsid.conf \
-e enablesid.conf -m /usr/local/etc/snort/sid-msg.map \
-h /var/log/sid_changes.log -I security -H
Prossimo esempio, come il precedente ma specificando che vogliamo -K (Keep) i nomi dei tarball originali e scriverli in /usr/local/etc/snort/rules/
./pulledpork.pl -c pulledpork.conf -i disablesid.conf -b dropsid.conf \
-e enablesid.conf -m /usr/local/etc/snort/sid-msg.map \
-h /var/log/sid_changes.log -I security -H -K /usr/local/etc/snort/rules/
Per gli utenti di Suricata, sono necessari gli stessi passaggi per quanto riguarda la posizione dei file di installazione, ma tutto ciò di cui pulledpork ha bisogno per elaborare i file di regole è il flag -S impostato su suricata-3.1.3 o qualsiasi versione di suricata in uso.
./pulledpork.pl -c pulledpork.conf -S suricata-3.1.3
Pulledpork "dovrebbe" funzionare con le regole Suricata ed ET/ETPro. Tuttavia non c'è supporto per le regole Talos su Suricata.