Network monitoring is very important in todays world. The internet is a scary place. People have taken steps to raise their awareness by installing In...
You will need the following: -An IDS running SNORT http://www.snort.org/ -Arduino Uno -Arduino Ethernet Shield -Arduino Proto Shield -10x 470Ω resis...
The VTLI process runs on the IDS and the Arduino. The Arduino listens for incoming connections to update the display. The IDS machine has a python s...
You need to attach the ethernet shield to the Arduino Uno, take note of the MAC address. Change this in the code attached. Also assign an IP address t...
You will need to solder the LED bar graph to the Proto Board. Use pins 2-9 for the first 8 LEDS and pins 14,15 for the last two. Pins 10-13 are used ...
On the IDS you will run a python script that connects to the a listener on the Arduino. Run this out of cron, say every 5 minutes for a constantly upd...
Now that everything is running, you can tune the maxAlerts variable to suit your environment so you are not always in the red. You have now ...
Step 7: Watch and Tune
Now that everything is running, you can tune the maxAlerts variable to suit your environment so you are not always in the red.
You have now moved your IDS signatures off of the screen and in to the real world, hopefully improving your situational awareness. Also you got to play with Arduinos!
Could you make an instuctable showing us how to do this with the xbee wifi protoshield. Personally I think that would be more helpful because then it could be placed anywhere within the networks range.
Hello Joe, Thank you for the great project. Like S.Gleason pointed, if you could assemble one with Xbee, I would be highly interested in it. You may also have a thorough user info along with that. I am not a great Computer wizzard like you nice guys !! Kindly respond to my mail if that is possible, please. Thanks. Sincerely KJ Kumar kjkumarsfo@yahoo.com
Sweet I can't wait to see it. I don't have an arduino yet or the knowledge of how snort works, but I thought that if you made it with an xbee it would be much easier to put into same sort of frame and keep around the house, or bring it into your living room while watching tv.
joe (author)
in reply to nubzzzFeb 20, 2012. 10:32 AMReply
Hey Nubuzz- If Suricata has a log, then it would work. If you can give me a sample of 2 lines from the log file, I'll update the python to have a suricata/snort switch.
Bio:I like to tinker with just about anything, sometimes it works out in the end. Have fun looking at the projects, try tearing something open and let me know how it goes. cheers, -Joe
PDF Downloads As a Pro member, you will gain access to download any Instructable in the PDF format.
You also have the ability to customize your PDF download.
-Joe
Like S.Gleason pointed, if you could assemble one with Xbee, I would be highly interested in it. You may also have a thorough user info along with that.
I am not a great Computer wizzard like you nice guys !!
Kindly respond to my mail if that is possible, please.
Thanks.
Sincerely
KJ Kumar
kjkumarsfo@yahoo.com
-Joe
http://www.instructables.com/id/Visual-Network-Threat-Level-Indicator-v2/
Thanks for looking.
-Joe
-Joe