5 Jul 2000 05:19
Argus 2.0 features
Russell Fulton <r.fulton <at> auckland.ac.nz>
2000-07-05 03:19:53 GMT
2000-07-05 03:19:53 GMT
Hi All, My main interest in argus is two fold, firstly as a tool for detecting threatening or anomolous traffic and secondly as an audit tool for forensic investigations. The current version of argus is an very good for that latter purpose but has significant weaknesses in the former role. In particular it does not do a very good job of logging single packets that do not conform to the normal tcp state transitions. Carter has done a great deal over the last couple of years to improve argus in this respect (Thanks!) but he has now run up against the storage limitations of the current audit record. So what I would like to initiate here is a discussion amongst those of us involved in Misuse detection (for want of a better term). The question is what new features do we want from Argus? Here one idea of the top of my head: 1/ the ability to log tcp packets that are anomalous, e.g. packets with illegal combinations of flags. 2/ the logging of more complete information for such packets (perhaps the best way to do this would be to have a new record class for such packets. 3/ When such packets are detected the should be written out immediately. There are some cases where it is not straight forward to decide if a packet is anomolous or not e.g. a packet with ACK of FIN set where there is no established tcp stream. It may be a tcp-ping or FIN scan(Continue reading)
>
> I thought of a fast and wide scsi disk and 128MB memory 500Mhz
> processor. Not taking the standard IDE disks increases the price
> considerably does anyone have a feeling for what difference this will
> make to performance?
Well I can probably help here
. At the moment I have my production
Argus server (P2 450, 256 Megs, dual 9 gig fast wide SCSI):
ids /kernel: CPU: Pentium II (quarter-micron) (451.02-MHz 686-class CPU)
ids /kernel: Origin = "GenuineIntel" Id = 0x652 Stepping=2
ids /kernel: Features=0x183fbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,C X8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,MMX,<b24>>
ids /kernel: real memory = 268435456 (262144K bytes)
ids /kernel: ahc0: <Adaptec aic7890/91 Ultra2 SCSI adapter> rev 0x00 int a irq 10 on pci0.14.0
ids /kernel: ahc0: aic7890/91 Wide Channel A, SCSI Id=7, 16/255 SCBs
ids /kernel: fxp0: <Intel EtherExpress Pro 10/100B Ethernet> rev 0x05 int a irq 9 on pci0.18.0
ids /kernel: da1: <WDIGTL WDE9100 1.50> Fixed Direct Access SCSI 2 device
ids /kernel: da1: 40.0MB/s transfers (20.0MHz, offset 15, 16bit)
ids /kernel: da1: 8683MB (17783204 512 byte sectors: 255H 63S/T1106C)
ids /kernel: da0 at ahc0 bus 0 target 0 lun 0
ids /kernel: da0: <WDIGTL WDE9100 1.50> Fixed Direct Access SCSI2 device
ids /kernel: da0: 40.0MB/s transfers (20.0MHz, offset 15, 16bit)
ids /kernel: da0: 8683MB (17783204 512 byte sectors: 255H 63S/T1106C)
RSS Feed