Bro 是一个开源的网络分析框架,侧重于网络安全监控。这是一项长达 15 年的研究成果,被各大学、研究实验室、超级计算机中心和许多开放科学界广泛使用。 -- Giuseppe Molica
本文导航
-简介:Bro 网络分析框架 …… 02%
-准备工作 …… 15%
-起步 …… 23%
-构建 Bro …… 36%
-安装 Bro …… 45%
-配置 Bro …… 48%
-使用 BroControl 管理 Bro 的安装 …… 81%
-结论 …… 90%
编译自: https://www.unixmen.com/how-to-install-bro-ubuntu-1604/
作者: Giuseppe Molica
译者: firmianay
# apt-get install cmake make gcc g++ flex bison libpcap-dev libssl-dev python-dev swig zlib1g-dev
$ wget http://geolite.maxmind.com/download/geoip/database/GeoLiteCity.dat.gz
$wget http://geolite.maxmind.com/download/geoip/database/GeoLiteCityv6-beta/GeoLiteCityv6.dat.gz
$ gzip -d GeoLiteCity.dat.gz
$ gzip -d GeoLiteCityv6.dat.gz
# mvGeoLiteCity.dat /usr/share/GeoIP/GeoIPCity.dat
# mv GeoLiteCityv6.dat /usr/share/GeoIP/GeoIPCityv6.dat
$ git clone --recursive git://git.bro.org/bro
$ cd bro
$ ./configure
$ make
# make install
# $EDITOR /usr/local/bro/etc/broctl.cfg
# Recipient address for emails sent out by Bro and BroControl
MailTo = admin@example.com
# $EDITOR /usr/local/bro/etc/node.cfg
[bro]
type=standalone
host=localhost
interface=eth0
# $EDITOR /usr/local/bro/etc/networks.cfg
# List of local networks in CIDR notation, optionally followed by a
# descriptive tag.
# For example, "10.0.0.0/8" or "fe80::/64" are valid prefixes.
10.0.0.0/8 Private IP space
172.16.0.0/12 Private IP space
192.168.0.0/16 Private IP space
X.X.X.X/X Public IP space
X.X.X.X/X Private IP space
# /usr/local/bro/bin/broctl
# /usr/local/bro/bin/broctl status
Name Type Host Status Pid Started
bro standalone localhost running 6807 20 Jul 12:30:50
欢迎光临 51学通信论坛2017新版 (http://bbs.51xuetongxin.com/) | Powered by Discuz! X3 |