D4 Project
Open and collaborative network monitoring
D4 project
Team CIRCL https://www.d4-project.org/
20190207 Alexandre Dulaunoy - Sami Mokaddem
D4 project https://www.d4-project.org/ 20190207 Alexandre Dulaunoy - - PowerPoint PPT Presentation
D4 Project Open and collaborative network monitoring Team CIRCL D4 project https://www.d4-project.org/ 20190207 Alexandre Dulaunoy - Sami Mokaddem P roblem statement CSIRTs (or private organisations) build their own honeypot, honeynet or
20190207 Alexandre Dulaunoy - Sami Mokaddem
1 27
1https://github.com/MISP/MISP
2 27
2https://www.github.com/D4-project/d4-core 3https://www.github.com/D4-project/d4-goclient/
3 27
pcap
D4 projectpcap and pdns
D4 projectpcap
D4 projectpdns
D4 projectpcap
D4 projectD4 server
D4 project
analyzer-d4-passivedns
D4 project
analyzer-d4-ddos
D4 project
Threat SharingCSIRTs - MeliCERTes Passive DNS lookup
D4 project
D4 project - global overview (20190127) sensor d4-core analyzer d4 encapsulation protocol MISP synchronisation d4 server-analyzer protocol ReST API
4 27
5 27
6 27
7 27
8 27
{ " type " : " ja3−j l " , " encoding " : " utf −8", " tags " : [ " tlp : white " ] , "misp : org " : "5 b642239−4db4−4580−adf4−4ebd950d210f " }
9 27
4https://github.com/D4-project/d4-core
10 27
11 27
◮ Check if a new session is created and valid data are saved in a Redis stream ◮ Launch a new Worker for each session
◮ Get data from a stream ◮ Reconstruct data ◮ Save data on disk (with file rotation) ◮ Save data in Redis. Create a queue for D4 Analyzer(s)
12 27
13 27
14 27
15 27
16 27
17 27
18 27
19 27
20 27
21 27
22 27
23 27
◮ Detect failure/addition of intermediate network equipments, firewalls, proxy servers etc ◮ Detect DDoS mitigation devices or services
24 27
5https://tools.ietf.org/html/rfc3168
25 27
6https://github.com/D4-project/analyzer-d4-pibs
26 27
27 / 27