Observations on the modern NSM toolchest
Christian Kreibich
christian@lastline.com
Bro4Pros, March 2016
1
Observations on the modern NSM toolchest Christian Kreibich - - PowerPoint PPT Presentation
Observations on the modern NSM toolchest Christian Kreibich christian@lastline.com Bro4Pros, March 2016 1 About me 2 For the Bro oldtimers my fault 3 4 The open-source NSM toolchest... or ? 5 Background on Lastline 6 Lastline
Christian Kreibich
christian@lastline.com
Bro4Pros, March 2016
1
2
3
4
5
6
7
8
9
infrastructure, with added control
ZeroMQ, Protobuf, Puppet, Ansible, Suricata, PF_RING, netmap, ...
10
11
12
13
(as open-source)
14
15
Vortex, ... netmap pcap pf_ring packetbricks
16
Vortex, ...
17
18
19
20
libnids: dead. Bro: ~3,000 lines with reusable core logic Snort: ~12,000 lines Suricata: ~10,000 lines (excluding unit tests) Wireshark: ~6,000 lines (excluding MPTCP)
21
22
23
24
25
26
27
libreass
28
libsigmatch
29
libprotoparse
30
31
32
33
Open-source release models matter
34
poses enormous risks
Licensing is really important
35
adoption
36
37
38
39
40
41
42
(btw, Lastline is hiring) Christian Kreibich
christian@lastline.com @ckreibich