Visual Network Threat Level Indicator

 by joe
FeaturedContest Winner

Step 7: Watch and Tune

IMG_4832.JPG

Now that everything is running, you can tune the maxAlerts variable to suit your environment so you are not always in the red.
You have now moved your IDS signatures off of the screen and in to the real world, hopefully improving your situational awareness. Also you got to play with Arduinos!

Thanks for looking!

-Joe
 
 
Remove these adsRemove these ads by Signing Up
sgleason1 says: Feb 19, 2012. 7:25 AM
Could you make an instuctable showing us how to do this with the xbee wifi protoshield. Personally I think that would be more helpful because then it could be placed anywhere within the networks range.
joe (author) in reply to sgleason1Feb 19, 2012. 7:33 AM
Hey SGleason1 - I would love to make one of these with an Xbee. It will have to wait until I buy one though!

-Joe
sreeci in reply to joeFeb 20, 2012. 1:24 AM
Hello Joe, Thank you for the great project.
Like S.Gleason pointed, if you could assemble one with Xbee, I would be highly interested in it. You may also have a thorough user info along with that.
I am not a great Computer wizzard like you nice guys !!
Kindly respond to my mail if that is possible, please.
Thanks.
Sincerely
KJ Kumar
kjkumarsfo@yahoo.com
joe (author) in reply to sreeciFeb 23, 2012. 7:34 PM
Hey Sreeci and Sgleason - I ordered up an Xbee. So I'll post a new wireless instructable up when I get it in.

-Joe
sgleason1 in reply to joeFeb 24, 2012. 7:39 AM
Sweet I can't wait to see it. I don't have an arduino yet or the knowledge of how snort works, but I thought that if you made it with an xbee it would be much easier to put into same sort of frame and keep around the house, or bring it into your living room while watching tv.
joe (author) in reply to sgleason1Feb 27, 2012. 8:16 PM
Hey Sreeci and Sgleason - Here is a wireless version of the device:
http://www.instructables.com/id/Visual-Network-Threat-Level-Indicator-v2/

Thanks for looking.

-Joe
nubzzz says: Feb 19, 2012. 10:29 PM
How do you think this would do running with Suricata instead of Snort?
joe (author) in reply to nubzzzFeb 20, 2012. 10:32 AM
Hey Nubuzz- If Suricata has a log, then it would work. If you can give me a sample of 2 lines from the log file, I'll update the python to have a suricata/snort switch.

-Joe
Pro

Get More Out of Instructables

Already have an Account?

close

PDF Downloads
As a Pro member, you will gain access to download any Instructable in the PDF format. You also have the ability to customize your PDF download.

Upgrade to Pro today!